Doomsday Sv_HandlePacket() underflow
| doomsday-svhandlepacket-underflow (36338) |
Description:
Doomsday is vulnerable to an integer underflow, caused by improper handling of chat messages by the Sv_HandlePacket() function. By sending a specially-crafted PKT_CHAT packet, a remote attacker could attempt to allocate an overly large amount of memory which could cause the application to crash.
Platforms Affected:
- Gentoo, Linux
- Jaakko Keränen, Doomsday 1.9.0-b5.1 and prior
Remedy:
No remedy available as of December 2007.
Consequences:
Denial of Service
References:
- Doomsday Web site, Doomsday HQ: Recent News at http://www.doomsdayhq.com/.
- Luigi Auriemma Advisory 29 Aug 2007, Multiple vulnerabilities in Doomsday 1.9.0-beta5.1 at http://aluigi.altervista.org/adv/dumsdei-adv.txt.
- BID-25483: Doomsday Engine Multiple Remote Vulnerabilities
- CVE-2007-4643: Integer underflow in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via a PKT_CHAT packet with a data length less than 3, which triggers an erroneous malloc, possibly related to the Sv_HandlePacket function in sv_main.c.
- GLSA-200802-02: Doomsday: Multiple vulnerabilities
- SA26524: Doomsday Multiple Vulnerabilities
- SA28821: Gentoo doomsday Multiple Vulnerabilities
Reported:
Aug 29, 2007
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
