Vulnerabilities > CVE-2006-4024 - Remote Heap Buffer Overflow vulnerability in Festalon 0.5.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
festalon
exploit available

Summary

The FESTAHES_Load function in pce/hes.c in Festalon 0.5.0 through 0.5.5 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative LoadAddr value in a HES file, which is used as an offset in a memcpy operation and leads to a buffer underflow.

Vulnerable Configurations

Part Description Count
Application
Festalon
2

Exploit-Db

descriptionFestalon 0.5 HES Files Remote Heap Buffer Overflow Vulnerability. CVE-2006-4024. Dos exploits for multiple platform
idEDB-ID:28361
last seen2016-02-03
modified2006-08-07
published2006-08-07
reporterLuigi Auriemma
sourcehttps://www.exploit-db.com/download/28361/
titleFestalon 0.5 HES Files Remote Heap Buffer Overflow Vulnerability