The enet_protocol_handle_send_fragment function in protocol.c for ENet library CVS version...
Vulnerability Description
The enet_protocol_handle_send_fragment function in protocol.c for ENet library CVS version Jul 2005 and earlier, as used in products including (1) Cube, (2) Sauerbraten, and (3) Duke3d_w32, allows remote attackers to cause a denial of service (application crash) via a packet fragment with a large total data size, which triggers an application abort when memory allocation fails.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-1195
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/043541.html
- http://www.securityfocus.com/archive/1/427465/100/0/threaded
- http://securitytracker.com/id?1015767
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25158
- http://www.securityfocus.com/bid/17087
- http://secunia.com/advisories/19208
- http://www.vupen.com/english/advisories/2006/0940
- http://aluigi.altervista.org/adv/enetx-adv.txt
- http://www.osvdb.org/23845
Affected Vendor
enet
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.