CVE Database
/

CVE-2007-4642

Back to search

CVE-2007-4642

Published: Aug 31, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple buffer overflows in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allow remote attackers to execute arbitrary code via a long chat (PKT_CHAT) message that is not properly handled by the (1) D_NetPlayerEvent function in d_net.c or the (2) Msg_Write function in net_msg.c, or (3) many commands that are not properly handled by the NetSv_ReadCommands function in d_netsv.c; or (4) cause a denial of service (daemon crash) via a chat (PKT_CHAT) message without a final '\0' character.

VendorProductVersions

n/a

n/a

affected
n/a

References

3084
third-party-advisory
x_refsource_SREASON
28821
third-party-advisory
x_refsource_SECUNIA
doomsday-dnetplayerevent-bo(36332)
vdb-entry
x_refsource_XF
26524
third-party-advisory
x_refsource_SECUNIA
doomsday-msgwrite-bo(36333)
vdb-entry
x_refsource_XF
25483
vdb-entry
x_refsource_BID
GLSA-200802-02
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now