|
|
| |
|
| |
freeciv: denial of service
| Package(s): | freeciv |
CVE #(s): | CVE-2006-3913
|
| Created: | August 1, 2006 |
Updated: | August 4, 2006 |
| Description: |
A buffer overflow in Freeciv 2.1.0-beta1 and earlier, and SVN from July 15,
2006 and earlier, allows remote attackers to cause a denial of service
(crash) and possibly execute arbitrary code via a (1) negative chunk_length
or a (2) large chunk->offset value in a PACKET_PLAYER_ATTRIBUTE_CHUNK
packet in the generic_handle_player_attribute_chunk function in
common/packets.c, and (3) a large packet->length value in the
handle_unit_orders function in server/unithand.c. |
| Alerts: |
|
( Log in to post comments)
|
|
|