Vulnerability Description
Call of Duty 4 (CoD4) 1.5 and earlier allows remote authenticated users to cause a denial of service (crash) via a type 7 stats packet, which triggers a memcpy with a negative value.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Activision | Call Of Duty 4 | <= 1.5 |
Related Weaknesses (CWE)
References
- http://aluigi.altervista.org/adv/cod4statz-adv.txt
- http://secunia.com/advisories/30050Vendor Advisory
- http://securityreason.com/securityalert/3858
- http://www.securityfocus.com/archive/1/491564/100/0/threaded
- http://www.securityfocus.com/bid/29026
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42163
- http://aluigi.altervista.org/adv/cod4statz-adv.txt
- http://secunia.com/advisories/30050Vendor Advisory
- http://securityreason.com/securityalert/3858
- http://www.securityfocus.com/archive/1/491564/100/0/threaded
- http://www.securityfocus.com/bid/29026
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42163
FAQ
What is CVE-2008-2106?
CVE-2008-2106 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Call of Duty 4 (CoD4) 1.5 and earlier allows remote authenticated users to cause a denial of service (crash) via a type 7 stats packet, which triggers a memcpy with a negative value.
How severe is CVE-2008-2106?
CVE-2008-2106 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-2106?
Check the references section above for vendor advisories and patch information. Affected products include: Activision Call Of Duty 4.