Vulnerabilities > CVE-2006-4024 - Remote Heap Buffer Overflow vulnerability in Festalon 0.5.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
The FESTAHES_Load function in pce/hes.c in Festalon 0.5.0 through 0.5.5 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative LoadAddr value in a HES file, which is used as an offset in a memcpy operation and leads to a buffer underflow.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description | Festalon 0.5 HES Files Remote Heap Buffer Overflow Vulnerability. CVE-2006-4024. Dos exploits for multiple platform |
id | EDB-ID:28361 |
last seen | 2016-02-03 |
modified | 2006-08-07 |
published | 2006-08-07 |
reporter | Luigi Auriemma |
source | https://www.exploit-db.com/download/28361/ |
title | Festalon 0.5 HES Files Remote Heap Buffer Overflow Vulnerability |