[Forgot Password]
Login  Register Subscribe

23631

 
 

122183

 
 

98060

 
 

909

 
 

79198

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2008-3286

Date: (C)2008-07-24   (M)2017-08-08 


SWAT 4 1.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via a (1) VERIFYCONTENT or (2) GAMECONFIG command sent to the server before user session initialization, which triggers a NULL pointer dereference; or (3) a GAMESPYRESPONSE command followed by a long RS string.

CVSS Score: 5.0Access Vector: NETWORK
Exploit Score: 10.0Access Complexity: LOW
Impact Score: 2.9Authentication: NONE
 Confidentiality: NONE
 Integrity: NONE
 Availability: PARTIAL





Reference:
BID-30299
SECUNIA-31158
ADV-2008-2149
http://aluigi.altervista.org/adv/swat4x-adv.txt
http://aluigi.org/fakep/unrealfp.zip
swat4-gamespyresponse-dos(43902)
swat4-verifycontent-gameconfig-dos(43901)

CWE    1
CWE-20

© 2013 SecPod Technologies