Vulnerability Description
Multiple buffer overflows in Deliantra Server before 2.82 allow remote attackers to execute arbitrary code via vectors related to (1) the command_gsay function in server/c_party.C and (2) the book implementation.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Deliantra | Deliantra | <= 2.81 |
Related Weaknesses (CWE)
References
- http://cvs.schmorp.de/deliantra/server/Changes?pathrev=rel-2_82
- http://cvs.schmorp.de/deliantra/server/server/c_party.C?r1=1.29&r2=1.30Patch
- http://secunia.com/advisories/37317Vendor Advisory
- http://www.osvdb.org/59878
- http://www.osvdb.org/59879
- http://www.vupen.com/english/advisories/2009/3176Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54205
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54206
- http://cvs.schmorp.de/deliantra/server/Changes?pathrev=rel-2_82
- http://cvs.schmorp.de/deliantra/server/server/c_party.C?r1=1.29&r2=1.30Patch
- http://secunia.com/advisories/37317Vendor Advisory
- http://www.osvdb.org/59878
- http://www.osvdb.org/59879
- http://www.vupen.com/english/advisories/2009/3176Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54205
FAQ
What is CVE-2009-4846?
CVE-2009-4846 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Multiple buffer overflows in Deliantra Server before 2.82 allow remote attackers to execute arbitrary code via vectors related to (1) the command_gsay function in server/c_party.C and (2) the book imp...
How severe is CVE-2009-4846?
CVE-2009-4846 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-4846?
Check the references section above for vendor advisories and patch information. Affected products include: Deliantra Deliantra.