{"api_version":"1","generated_at":"2026-07-23T09:40:30+00:00","cve":"CVE-2007-4508","urls":{"html":"https://cve.report/CVE-2007-4508","api":"https://cve.report/api/cve/CVE-2007-4508.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4508","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4508"},"summary":{"title":"CVE-2007-4508","description":"Stack-based buffer overflow in Rebellion Asura engine, as used for the server in Rogue Trooper 1.0 and earlier and Prism 1.1.1.0 and earlier, allows remote attackers to execute arbitrary code via a long string in a 0xf007 packet for the challenge B query.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-08-23 19:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36221","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36221","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://aluigi.altervista.org/adv/asurabof-adv.txt","name":"http://aluigi.altervista.org/adv/asurabof-adv.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/3053","name":"http://securityreason.com/securityalert/3053","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityReason - Buffer-overflow in the Asura engine","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/24023","name":"http://secunia.com/advisories/24023","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PRISM Guard Shield Asura Engine Packet Handling Buffer Overflow - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26571","name":"http://secunia.com/advisories/26571","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Rogue Trooper Asura Engine Packet Handling Buffer Overflow - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/25411","name":"http://www.securityfocus.com/bid/25411","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Asura Engine Challenge B Query Remote Stack Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/477357/100/0/threaded","name":"http://www.securityfocus.com/archive/1/477357/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/39799","name":"http://osvdb.org/39799","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2007/2955","name":"http://www.vupen.com/english/advisories/2007/2955","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/2956","name":"http://www.vupen.com/english/advisories/2007/2956","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4508","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4508","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4508","vulnerable":"1","versionEndIncluding":"1.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rebellion","cpe5":"rogue_trooper","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4508","vulnerable":"1","versionEndIncluding":"1.1.1.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rival_interactive","cpe5":"prism","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:01:09.295Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2007-2956","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2956"},{"name":"20070822 Buffer-overflow in the Asura engine","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/477357/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://aluigi.altervista.org/adv/asurabof-adv.txt"},{"name":"39799","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/39799"},{"name":"ADV-2007-2955","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2955"},{"name":"25411","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25411"},{"name":"26571","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26571"},{"name":"24023","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/24023"},{"name":"3053","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/3053"},{"name":"prism-guard-asura-engine-bo(36221)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36221"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-08-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in Rebellion Asura engine, as used for the server in Rogue Trooper 1.0 and earlier and Prism 1.1.1.0 and earlier, allows remote attackers to execute arbitrary code via a long string in a 0xf007 packet for the challenge B query."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-15T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2007-2956","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2956"},{"name":"20070822 Buffer-overflow in the Asura engine","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/477357/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://aluigi.altervista.org/adv/asurabof-adv.txt"},{"name":"39799","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/39799"},{"name":"ADV-2007-2955","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2955"},{"name":"25411","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25411"},{"name":"26571","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26571"},{"name":"24023","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/24023"},{"name":"3053","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/3053"},{"name":"prism-guard-asura-engine-bo(36221)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36221"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-4508","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in Rebellion Asura engine, as used for the server in Rogue Trooper 1.0 and earlier and Prism 1.1.1.0 and earlier, allows remote attackers to execute arbitrary code via a long string in a 0xf007 packet for the challenge B query."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2007-2956","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2956"},{"name":"20070822 Buffer-overflow in the Asura engine","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/477357/100/0/threaded"},{"name":"http://aluigi.altervista.org/adv/asurabof-adv.txt","refsource":"MISC","url":"http://aluigi.altervista.org/adv/asurabof-adv.txt"},{"name":"39799","refsource":"OSVDB","url":"http://osvdb.org/39799"},{"name":"ADV-2007-2955","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2955"},{"name":"25411","refsource":"BID","url":"http://www.securityfocus.com/bid/25411"},{"name":"26571","refsource":"SECUNIA","url":"http://secunia.com/advisories/26571"},{"name":"24023","refsource":"SECUNIA","url":"http://secunia.com/advisories/24023"},{"name":"3053","refsource":"SREASON","url":"http://securityreason.com/securityalert/3053"},{"name":"prism-guard-asura-engine-bo(36221)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36221"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-4508","datePublished":"2007-08-23T19:00:00.000Z","dateReserved":"2007-08-23T00:00:00.000Z","dateUpdated":"2024-08-07T15:01:09.295Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-08-23 19:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:rebellion:rogue_trooper:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0","matchCriteriaId":"83D8B74F-D1A1-4EA2-A1AD-9996555B6553"},{"vulnerable":true,"criteria":"cpe:2.3:a:rival_interactive:prism:*:*:*:*:*:*:*:*","versionEndIncluding":"1.1.1.0","matchCriteriaId":"E71C1D69-2A87-4370-A4B4-0355B027B6BF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4508","Ordinal":"1","Title":"CVE-2007-4508","CVE":"CVE-2007-4508","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4508","Ordinal":"1","NoteData":"Stack-based buffer overflow in Rebellion Asura engine, as used for the server in Rogue Trooper 1.0 and earlier and Prism 1.1.1.0 and earlier, allows remote attackers to execute arbitrary code via a long string in a 0xf007 packet for the challenge B query.","Type":"Description","Title":"CVE-2007-4508"},{"CveYear":"2007","CveId":"4508","Ordinal":"2","NoteData":"2007-08-23","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4508","Ordinal":"3","NoteData":"2018-10-15","Type":"Other","Title":"Modified"}]}}}