Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gjv2-xrpp-rpmg

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_pkg function (packets.c) to use this data size when sending a reply, and allows remote attackers to read portions of server memory.

The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_pkg function (packets.c) to use this data size when sending a reply, and allows remote attackers to read portions of server memory.

EPSS

Процентиль: 93%
0.12503
Средний

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 19 лет назад

The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_pkg function (packets.c) to use this data size when sending a reply, and allows remote attackers to read portions of server memory.

nvd
больше 19 лет назад

The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_pkg function (packets.c) to use this data size when sending a reply, and allows remote attackers to read portions of server memory.

debian
больше 19 лет назад

The do_gameinfo function in BomberClone 0.11.6 and earlier, and possib ...

EPSS

Процентиль: 93%
0.12503
Средний

Дефекты

CWE-200