|
| Package(s): | Doomsday |
CVE #(s): | CVE-2007-4642
CVE-2007-4643
CVE-2007-4644
|
| Created: | February 7, 2008 |
Updated: | February 13, 2008 |
| Description: |
From the Gentoo alert:
Luigi Auriemma discovered multiple buffer overflows in the
D_NetPlayerEvent() function, the Msg_Write() function and the
NetSv_ReadCommands() function. He also discovered errors when handling
chat messages that are not NULL-terminated (CVE-2007-4642) or contain a
short data length, triggering an integer underflow (CVE-2007-4643).
Furthermore a format string vulnerability was discovered in the
Cl_GetPackets() function when processing PSV_CONSOLE_TEXT messages
(CVE-2007-4644).
This vulnerability can be used for the execution of arbitrary code
or to create a denial of service. |
| Alerts: |
|
( Log in to post comments)
|