Vulnerabilities > CVE-2006-4024 - Unspecified vulnerability in Festalon 0.5.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN festalon
exploit available
Summary
The FESTAHES_Load function in pce/hes.c in Festalon 0.5.0 through 0.5.5 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative LoadAddr value in a HES file, which is used as an offset in a memcpy operation and leads to a buffer underflow.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description | Festalon 0.5 HES Files Remote Heap Buffer Overflow Vulnerability. CVE-2006-4024. Dos exploits for multiple platform |
id | EDB-ID:28361 |
last seen | 2016-02-03 |
modified | 2006-08-07 |
published | 2006-08-07 |
reporter | Luigi Auriemma |
source | https://www.exploit-db.com/download/28361/ |
title | Festalon 0.5 HES Files Remote Heap Buffer Overflow Vulnerability |
References
- http://aluigi.altervista.org/adv/festahc-adv.txt
- http://aluigi.altervista.org/adv/festahc-adv.txt
- http://secunia.com/advisories/21367
- http://secunia.com/advisories/21367
- http://www.securityfocus.com/bid/19402
- http://www.securityfocus.com/bid/19402
- http://www.vupen.com/english/advisories/2006/3177
- http://www.vupen.com/english/advisories/2006/3177