Vulnerabilities > CVE-2006-1593 - Resource Management Errors vulnerability in multiple products

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
x-doom
zdaemon
CWE-399
exploit available

Summary

The (1) ZD_MissingPlayer, (2) ZD_UseItem, and (3) ZD_LoadNewClientLevel functions in sv_main.cpp for (a) Zdaemon 1.08.01 and (b) X-Doom allows remote attackers to cause a denial of service (crash) via an invalid player slot or item number, which causes an invalid memory access, possibly due to an invalid array index.

Vulnerable Configurations

Part Description Count
Application
X-Doom
1
Application
Zdaemon
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionZDaemon 1.8.1 Multiple Remote Vulnerabilities. CVE-2006-1593. Dos exploits for multiple platform
idEDB-ID:27547
last seen2016-02-03
modified2006-03-31
published2006-03-31
reporterLuigi Auriemma
sourcehttps://www.exploit-db.com/download/27547/
titlezdaemon 1.8.1 - Multiple Vulnerabilities