Kaillera Message Buffer Overflow Vulnerability
BID:18871
CVE-2006-3491 |Info
Kaillera Message Buffer Overflow Vulnerability
| Bugtraq ID: | 18871 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3491 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2006 12:00AM |
| Updated: | Jul 06 2007 07:47PM |
| Credit: | Luigi Auriemma is credited with discovering this vulnerability. |
| Vulnerable: |
Kaillera Kaillera 0.86 |
| Not Vulnerable: | |
Discussion
Kaillera Message Buffer Overflow Vulnerability
Kaillera is prone to a buffer-overflow vulnerability because it fails to properly bounds-check messages before copying them to an insufficiently sized memory buffer.
Successful exploits can allow remote attackers to execute arbitrary machine code in the context of the user running the application.
Kaillera is prone to a buffer-overflow vulnerability because it fails to properly bounds-check messages before copying them to an insufficiently sized memory buffer.
Successful exploits can allow remote attackers to execute arbitrary machine code in the context of the user running the application.
Exploit / POC
Kaillera Message Buffer Overflow Vulnerability
A proof-of-concept exploit is available.
A proof-of-concept exploit is available.
Solution / Fix
Kaillera Message Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any official vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any official vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Kaillera Message Buffer Overflow Vulnerability
References:
References:
- Kaillera Homepage (Kaillera)
- Luigi Auriemma Homepage (Luigi Auriemma)
- Possible code execution in Kaillera 0.86 (Luigi Auriemma)