Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decrypt() when compiled using libsodium, leading to a Stack-Based Buffer Overflow and resulting in a memory corruption and possibly even a remote code execution.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: checkpoint

Published: 2020-12-02T01:01:38

Updated: 2024-08-04T08:47:40.942Z

Reserved: 2020-01-07T00:00:00

Link: CVE-2020-6018

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-12-02T01:15:12.967

Modified: 2022-04-12T16:19:58.543

Link: CVE-2020-6018

cve-icon Redhat

No data.