From 4f2d7949f03e1c198bc888f2d05f421d35c57e21 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Mon, 9 Oct 2017 18:53:29 +0100 Subject: reinit the tree, so we can have metadata --- metadata/glsa/glsa-200802-02.xml | 74 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 74 insertions(+) create mode 100644 metadata/glsa/glsa-200802-02.xml (limited to 'metadata/glsa/glsa-200802-02.xml') diff --git a/metadata/glsa/glsa-200802-02.xml b/metadata/glsa/glsa-200802-02.xml new file mode 100644 index 000000000000..936a472daba5 --- /dev/null +++ b/metadata/glsa/glsa-200802-02.xml @@ -0,0 +1,74 @@ + + + + Doomsday: Multiple vulnerabilities + + Multiple vulnerabilities in Doomsday might allow remote execution of + arbitrary code or a Denial of Service. + + doomsday + 2008-02-06 + 2008-02-10: 02 + 190835 + remote + + + 1.9.0_beta52 + + + +

+ The Doomsday Engine (deng) is a modern gaming engine for popular ID + games like Doom, Heretic and Hexen. +

+
+ +

+ Luigi Auriemma discovered multiple buffer overflows in the + D_NetPlayerEvent() function, the Msg_Write() function and the + NetSv_ReadCommands() function. He also discovered errors when handling + chat messages that are not NULL-terminated (CVE-2007-4642) or contain a + short data length, triggering an integer underflow (CVE-2007-4643). + Furthermore a format string vulnerability was discovered in the + Cl_GetPackets() function when processing PSV_CONSOLE_TEXT messages + (CVE-2007-4644). +

+
+ +

+ A remote attacker could exploit these vulnerabilities to execute + arbitrary code with the rights of the user running the Doomsday server + or cause a Denial of Service by sending specially crafted messages to + the server. +

+
+ +

+ There is no known workaround at this time. +

+
+ +

+ While some of these issues could be resolved in + "games-fps/doomsday-1.9.0-beta5.2", the format string vulnerability + (CVE-2007-4644) remains unfixed. We recommend that users unmerge + Doomsday: +

+ + # emerge --unmerge games-fps/doomsday +
+ + CVE-2007-4642 + CVE-2007-4643 + CVE-2007-4644 + + + rbu + + + rbu + + + rbu + +
-- cgit v1.2.3