Alien Arena 2007 6.10 and earlier allows remote attackers to cause a denial of service (client disconnect) by sending a client_connect command in a forged packet from the server to a client. NOTE: client IP addresses are available via product-specific queries.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://aluigi.altervista.org/adv/aa2k7x-adv.txt | |
http://secunia.com/advisories/26819 | third party advisory |
http://securityreason.com/securityalert/3105 | third party advisory |
http://www.securityfocus.com/bid/25559 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/36465 | vdb entry |
http://www.securityfocus.com/archive/1/478628/100/0/threaded | mailing list |
http://archives.neohapsis.com/archives/fulldisclosure/2007-09/0049.html | mailing list |
http://osvdb.org/40508 | vdb entry |
http://www.vupen.com/english/advisories/2007/3169 | vdb entry |
http://www.quakesrc.org/forums/viewtopic.php?t=6843&start=1 |