Carsten的3D Engine 格式化字符串漏洞

Carsten的3D Engine 格式化字符串漏洞

漏洞ID 1108497 漏洞类型 格式化字符串
发布时间 2005-03-03 更新时间 2005-10-20
图片[1]-Carsten的3D Engine 格式化字符串漏洞-安全小百科CVE编号 CVE-2005-0671
图片[2]-Carsten的3D Engine 格式化字符串漏洞-安全小百科CNNVD-ID CNNVD-200503-044
漏洞平台 Multiple CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/25190
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200503-044
|漏洞详情
Carsten的3DEngine(Ca3DE)2004年3月版本及更早版本中存在格式化字符串漏洞,远程攻击者可以通过指令中的格式化字符串限定符执行任意代码。
|漏洞EXP
source: http://www.securityfocus.com/bid/12727/info

Ca3DE is reported prone to multiple remote vulnerabilities. An attacker can exploit these issues to carry out format string and denial of service attacks.

The following specific issues were identified:

It is reported that all commands accepted by the server are affected by format string vulnerabilities.

A successful attack may result in crashing the application or lead to arbitrary code execution. This may facilitate unauthorized access or privilege escalation in the context of the application.

The application is also affected by a remote denial of service vulnerability.

Ca3DE versions released before March 2004 are affected by these issues. 

https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/bin-sploits/25190.zip
|参考资料

来源:BID
名称:12727
链接:http://www.securityfocus.com/bid/12727
来源:SECUNIA
名称:14483
链接:http://secunia.com/advisories/14483
来源:SECTRACK
名称:1013361
链接:http://securitytracker.com/id?1013361
来源:MISC
链接:http://aluigi.altervista.org/adv/ca3dex-adv.txt

相关推荐: Microsoft Internet Explorer Legacy文本格式化插件成分缓冲区溢出漏洞

Microsoft Internet Explorer Legacy文本格式化插件成分缓冲区溢出漏洞 漏洞ID 1106935 漏洞类型 缓冲区溢出 发布时间 2002-08-22 更新时间 2005-10-12 CVE编号 CVE-2002-0647 CNN…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享