CVE Database
/

CVE-2007-3917

Back to search

CVE-2007-3917

Published: Oct 11, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

The multiplayer engine in Wesnoth 1.2.x before 1.2.7 and 1.3.x before 1.3.9 allows remote servers to cause a denial of service (crash) via a long message with multibyte characters that can produce an invalid UTF-8 string after it is truncated, which triggers an uncaught exception, involving the truncate_message function in server/server.cpp. NOTE: this issue affects both clients and servers.

VendorProductVersions

n/a

n/a

affected
n/a

References

41711
vdb-entry
x_refsource_OSVDB
25995
vdb-entry
x_refsource_BID
27218
third-party-advisory
x_refsource_SECUNIA
FEDORA-2007-2496
vendor-advisory
x_refsource_FEDORA
wesnoth-utf8-dos(37047)
vdb-entry
x_refsource_XF
27241
third-party-advisory
x_refsource_SECUNIA
DSA-1386
vendor-advisory
x_refsource_DEBIAN
ADV-2007-3449
vdb-entry
x_refsource_VUPEN
27137
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now