First published: Fri Mar 10 2006(Updated: )
The Com_sprintf function in q_shared.c in Alien Arena 2006 Gold Edition 5.00 does not properly NULL terminate certain long strings, which allows remote attackers (possibly authenticated) to cause a denial of service (application crash) via a long skin, weapon, or model name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alien Arena | =gold_5.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-1147 is considered moderate due to its potential to cause application crashes.
To fix CVE-2006-1147, ensure you upgrade to a patched version that properly handles string termination.
CVE-2006-1147 affects users of Alien Arena 2006 Gold Edition version 5.00.
CVE-2006-1147 allows remote attackers to perform denial of service attacks through long strings.
Exploitation of CVE-2006-1147 may be possible by authenticated users, depending on the context.