|
|
| |
|
| |
nexuiz: arbitrary code execution, denial of service
| Package(s): | nexuiz |
CVE #(s): | CVE-2006-6609
CVE-2006-6610
|
| Created: | February 26, 2007 |
Updated: | February 28, 2007 |
| Description: |
Nexuiz fails to correctly validate input within "clientcommands". There is
also a failure to correctly handle connection attempts from remote hosts.
Using a specially crafted "clientcommand" a remote attacker can cause a
buffer overflow in Nexuiz which could result in the execution of arbitrary
code. Additionally, there is a Denial of Service vulnerability in Nexuiz
allowing an attacker to cause Nexuiz to crash or to run out of resources by
overloading it with specially crafted connection requests. |
| Alerts: |
|
( Log in to post comments)
|
|
|