First published: Thu Jul 06 2006(Updated: )
Papyrus NASCAR Racing 4 4.1.3.1.6 and earlier, 2002 Season 1.1.0.2 and earlier, and 2003 Season 1.2.0.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending an empty UDP datagram, which is not properly discarded due to use of the FIONREAD asynchronous socket.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Electronic Arts Nascar Racing | <=2003_season_1.2.1 | |
Electronic Arts Nascar Racing | <=4.1.3.1.6 | |
Electronic Arts Nascar Racing | <=2002_season_1.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3393 is classified as a denial of service vulnerability due to excessive CPU consumption caused by an empty UDP datagram.
To mitigate CVE-2006-3393, update to version 4.1.3.1.7 or later for Nascar Racing 4, or 2003 Season 1.2.1 or later.
CVE-2006-3393 affects Electronic Arts Nascar Racing versions 4.1.3.1.6 and earlier, 2002 Season 1.1.0.2 and earlier, and 2003 Season 1.2.0.1 and earlier.
Yes, CVE-2006-3393 can be exploited remotely by attackers sending an empty UDP datagram to the affected systems.
CVE-2006-3393 can lead to denial of service, making the game unresponsive and consuming significant CPU resources.