LWN.net Logo

nexuiz: arbitrary code execution, denial of service

Package(s):nexuiz CVE #(s):CVE-2006-6609 CVE-2006-6610
Created:February 26, 2007 Updated:February 28, 2007
Description: Nexuiz fails to correctly validate input within "clientcommands". There is also a failure to correctly handle connection attempts from remote hosts. Using a specially crafted "clientcommand" a remote attacker can cause a buffer overflow in Nexuiz which could result in the execution of arbitrary code. Additionally, there is a Denial of Service vulnerability in Nexuiz allowing an attacker to cause Nexuiz to crash or to run out of resources by overloading it with specially crafted connection requests.
Alerts:
Gentoo 200702-09 2007-02-25

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds