Secunia Logo
 
CVE Reference: CVE-2006-3913
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-3913

Description:
Buffer overflow in Freeciv 2.1.0-beta1 and earlier, and SVN 15 Jul 2006 and earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) negative chunk_length or a (2) large chunk->offset value in a PACKET_PLAYER_ATTRIBUTE_CHUNK packet in the generic_handle_player_attribute_chunk function in common/packets.c, and (3) a large packet->length value in the handle_unit_orders function in server/unithand.c.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/27955
  http://xforce.iss.net/xforce/xfdb/27956

SREASON
  http://securityreason.com/securityalert/1296

SAID
  Secunia Advisory: SA21171
  Secunia Advisory: SA21254
  Secunia Advisory: SA21352

MISC
  http://aluigi.altervista.org/adv/freecivx-adv.txt

MANDRIVA
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:135

DEBIAN
  http://www.debian.org/security/2006/dsa-1142

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/441042/100/0/threaded

BID
  19117


Return to the previous page.