The (1) sgetstr and (2) getint functions in Sauerbraten 2006_02_28, as derived from the Cube engine, allow remote attackers to cause a denial of service (segmentation fault) via long streams of input data that trigger an out-of-bounds read, as demonstrated using SV_EXT tag data in the Cube engine, which is not properly handled by getint.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2006-03-09T11:00:00

Updated: 2024-08-07T16:56:15.564Z

Reserved: 2006-03-09T00:00:00

Link: CVE-2006-1101

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2006-03-09T13:06:00.000

Modified: 2018-10-18T16:30:43.230

Link: CVE-2006-1101

cve-icon Redhat

No data.