Title : Gentoo Security Update Fixes Doomsday Multiple Remote Vulnerabilities VUPEN ID : VUPEN/ADV-2008-0434 CVE ID : CVE-2007-4642 - CVE-2007-4643 - CVE-2007-4644
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-02-07
Technical Description
Multiple vulnerabilities have been identified in Gentoo, which could be exploited by attackers to cause a denial of service or execute arbitrary code. These issues are caused by buffer overflow and format string errors in Doomsday when processing data via the "D_NetPlayerEvent()" "Msg_Write()", "NetSv_ReadCommands()" and "Cl_GetPackets()" functions, which could be exploited by attackers to crash an affected application or compromise a vulnerable system.