Skulltag before 0.97d2-RC6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) by sending a "command 29" packet when the player is not in the game.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
http://secunia.com/advisories/31427 | broken link third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44363 | vdb entry third party advisory |
http://www.vupen.com/english/advisories/2008/2325 | vdb entry broken link |
http://aluigi.altervista.org/adv/skulltagod-adv.txt | broken link |
http://skulltag.com/forum/viewtopic.php?f=1&t=14716 | patch broken link |