Doomsday Con_Message() and conPrintf() format string
| doomsday-conmessage-conprintf-format-string (25622) |
Description:
Doomsday could allow a remote attacker to execute arbitrary commands, caused by a format string vulnerability in the Con_Message() or conPrintf() functions. A remote attacker could send a specially-crafted JOIN command containing format specifiers to port 13209/tcp which would allow the attacker to execute arbitrary commands or cause the server to crash.
Platforms Affected:
- Gentoo, Linux
- Jaakko Keränen, Doomsday 1.8.6
- Jaakko Keränen, Doomsday SVN 1.9.0
Remedy:
For Gentoo Linux:
Refer to Gentoo Linux Security Announcement GLSA 2006-04-05 for patch, upgrade, or suggested workaround information. See References.
Consequences:
Gain Access
References:
- Doomsday Web site, Doomsday HQ: Recent News at http://www.doomsdayhq.com/news.php.
- Full-Disclosure Mailing List, Mon Apr 03 2006 - 16:20:34 CDT, Format string in Doomsday 1.8.6 at http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0053.html.
- BID-17369: Doomsday Multiple Remote Format String Vulnerabilities
- CVE-2006-1618: Format string vulnerability in the (1) Con_message and (2) conPrintf functions in con_main.c in Doomsday engine 1.8.6 allows remote attackers to execute arbitrary code via format string specifiers in an argument to the JOIN command, and possibly other command arguments.
- GLSA-200604-05: Doomsday: Format string vulnerability
- SA19515: Doomsday Format String Vulnerabilities
- SA19519: Gentoo Doomsday Format String Vulnerabilities
- SECTRACK ID: 1015860: Doomsday Engine Format String Bugs in Con_Message() and Con_Printf() Let Remote Users Execute Arbitrary Code
- VUPEN/ADV-2006-1221: Doomsday Con_Message and conPrintf Remote Format String Vulnerabilities
Reported:
Apr 04, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
