|
|
CrossFire "setup" Command Handling Remote Buffer Overflow Vulnerability
|
A vulnerability has been identified in CrossFire, which could be exploited by remote attackers to execute arbitrary commands. This flaw is due to a buffer overflow error in the "SetUp()" [request.c] function when processing a specially crafted "setup" command, which could be exploited by remote attackers to compromise a vulnerable system.
CrossFire version 1.9.0 and prior
VUPEN Security is not aware of any vendor-supplied patch.
http://www.vupen.com/english/advisories/2006/0951
Vulnerability reported by landser
2006-03-15 : Initial release
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|
|
|
Monthly Statistics |
 |
|
|
|
| |
|
Try VUPEN
VNS |
 |
|
 |
|
| |
|
 |
| |
|
|
|
|