Scrapland 1.0 and earlier allows remote attackers to cause a denial of service (server termination) by triggering an error, which is treated as a fatal error by the server, as demonstrated using (1) signed integers for size values, (2) an invalid model, (3) a "newpos" value that is less than or equal to a size value, or (4) partial packets.
References
Configurations
History
20 Nov 2024, 23:55
Type | Values Removed | Values Added |
---|---|---|
References | () http://aluigi.altervista.org/adv/scrapboom-adv.txt - | |
References | () http://marc.info/?l=full-disclosure&m=110961578504928&w=2 - | |
References | () http://secunia.com/advisories/14435 - Vendor Advisory |
Information
Published : 2005-05-02 04:00
Updated : 2024-11-20 23:55
NVD link : CVE-2005-0621
Mitre link : CVE-2005-0621
CVE.ORG link : CVE-2005-0621
JSON object : View
Products Affected
enlight_software
- scrapland
CWE