| ID | CVE-2006-1194 | ||||||
| Sažetak | Integer signedness error in the enet_protocol_handle_incoming_commands function in protocol.c for ENet library CVS version Jul 2005 and earlier, as used in products including (1) Cube, (2) Sauerbraten, and (3) Duke3d_w32, allows remote attackers to cause a denial of service (application crash) via a packet with a large command length value, which leads to an invalid memory access. | ||||||
| Reference |
|
||||||
| CVSS |
|
||||||
| Pristup |
|
||||||
| Impact |
|
||||||
| CVSS vektor | AV:N/AC:L/Au:N/C:N/I:N/A:P | ||||||
| Zadnje važnije ažuriranje | 18-10-2018 - 16:31 | ||||||
| Objavljeno | 13-03-2006 - 22:02 |

