Format string vulnerability in the safe_bprintf function in acesrc/acebot_cmds.c in Alien Arena 2007 6.10 and earlier allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in a nickname.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
http://aluigi.altervista.org/adv/aa2k7x-adv.txt | |
http://secunia.com/advisories/26819 | third party advisory |
http://securityreason.com/securityalert/3105 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/36463 | vdb entry |
http://osvdb.org/40507 | vdb entry |
http://www.securityfocus.com/bid/25559 | vdb entry exploit |
http://www.securityfocus.com/archive/1/478628/100/0/threaded | mailing list |
http://archives.neohapsis.com/archives/fulldisclosure/2007-09/0049.html | mailing list |
http://www.vupen.com/english/advisories/2007/3169 | vdb entry |
http://www.quakesrc.org/forums/viewtopic.php?t=6843&start=1 |