5
CVSSv2

CVE-2006-4005

Published: 07/08/2006 Updated: 20/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

BomberClone 0.11.6 and previous versions allows remote malicious users to cause a denial of service (daemon crash) via (1) a certain malformed PKGF_ackreq packet, which triggers a crash in the rscache_add() function in pkgcache.c; and (2) an error packet, which is intended to be received by clients and force client shutdown, but also triggers server shutdown.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bomberclone bomberclone 0.11.3

bomberclone bomberclone 0.11.6

bomberclone bomberclone 0.11.4

bomberclone bomberclone 0.11.5

Vendor Advisories

Debian Bug report logs - #382082 CVE-2006-400[56]: Multiple Remote Vulnerabilities in Bomberclone Package: bomberclone; Maintainer for bomberclone is Peter Spiess-Knafl <dev@spiessknaflat>; Source for bomberclone is src:bomberclone (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Tue, 8 Aug ...
Luigi Auriemma discovered two security related bugs in bomberclone, a free Bomberman clone The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2006-4005 The program copies remotely provided data unchecked which could lead to a denial of service via an application crash CVE-2006-4006 Bomberclone use ...