Vulnerability Description
Sauerbraten 2006_02_28, as derived from the Cube engine, allows remote attackers to cause a denial of service (client exit) by forcing the server to change to a map (ogz) file whose name contains ".." sequences and has a certain length that prevents the addition of the ".ogz" extension.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sauerbraten | Cube | 2005-08-09 |
| Sauerbraten | Sauerbraten | 2006-02-28 |
References
- http://aluigi.altervista.org/adv/evilcube-adv.txtExploitVendor Advisory
- http://secunia.com/advisories/19110
- http://secunia.com/advisories/19111
- http://secunia.com/advisories/19199
- http://securityreason.com/securityalert/548
- http://www.gentoo.org/security/en/glsa/glsa-200603-10.xml
- http://www.securityfocus.com/archive/1/426865/100/0/threaded
- http://www.securityfocus.com/archive/1/426867/100/0/threaded
- http://www.securityfocus.com/bid/16986Exploit
- http://www.vupen.com/english/advisories/2006/0847
- http://www.vupen.com/english/advisories/2006/0848
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25086
- http://aluigi.altervista.org/adv/evilcube-adv.txtExploitVendor Advisory
- http://secunia.com/advisories/19110
- http://secunia.com/advisories/19111
FAQ
What is CVE-2006-1102?
CVE-2006-1102 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Sauerbraten 2006_02_28, as derived from the Cube engine, allows remote attackers to cause a denial of service (client exit) by forcing the server to change to a map (ogz) file whose name contains ".."...
How severe is CVE-2006-1102?
CVE-2006-1102 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-1102?
Check the references section above for vendor advisories and patch information. Affected products include: Sauerbraten Cube, Sauerbraten Sauerbraten.