FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-3125

This CVE name corresponds to:

Entered Topic
2006-09-02 gtetrinet -- remote code execution

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-3125
Phase Assigned(20060621)

Description

Array index error in tetrinet.c in gtetrinet 0.7.8 and earlier allows remote attackers to execute arbitrary code via a packet specifying a negative number of players, which is used as an array index.

References

Source Reference
DEBIAN DSA-1163
GENTOO GLSA-200609-02
SUSE SUSE-SR:2006:021
BID 19766
OSVDB 28269
SECUNIA 21691
SECUNIA 21704
SECUNIA 21800
SECUNIA 21749
XF gtetrinet-array-indexing-code-execution(28683)