CVE-2007-3917
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The multiplayer engine in Wesnoth 1.2.x before 1.2.7 and 1.3.x before 1.3.9 allows remote servers to cause a denial of service (crash) via a long message with multibyte characters that can produce an invalid UTF-8 string after it is truncated, which triggers an uncaught exception, involving the truncate_message function in server/server.cpp. NOTE: this issue affects both clients and servers.
El motor multijugador en Wesnoth versiones 1.2.x anteriores a 1.2.7 y versiones 1.3.x anteriores a 1.3.9, permite a los servidores remotos causar una denegación de servicio (bloqueo) por medio de un mensaje largo con caracteres multibyte que puede producir una cadena UTF-8 no válida después que está truncado, lo que desencadena una excepción no detectada, que involucra la función truncate_message en el archivo server/server.cpp. NOTA: este problema afecta tanto a los clientes como a los servidores.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-07-20 CVE Reserved
- 2007-10-11 CVE Published
- 2024-08-07 CVE Updated
- 2024-09-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-134: Use of Externally-Controlled Format String
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://osvdb.org/41711 | Vdb Entry | |
http://svn.gna.org/viewcvs/wesnoth/tags/1.2.7/changelog?rev=20982&view=download | X_refsource_confirm | |
http://www.securityfocus.com/bid/25995 | Vdb Entry | |
http://www.wesnoth.org/forum/viewtopic.php?p=256618 | X_refsource_confirm | |
http://www.wesnoth.org/forum/viewtopic.php?t=18188 | X_refsource_confirm | |
https://bugzilla.redhat.com/show_bug.cgi?id=324841 | X_refsource_confirm | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/37047 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/27137 | 2017-07-29 | |
http://secunia.com/advisories/27218 | 2017-07-29 | |
http://secunia.com/advisories/27241 | 2017-07-29 | |
http://www.debian.org/security/2007/dsa-1386 | 2017-07-29 | |
http://www.vupen.com/english/advisories/2007/3449 | 2017-07-29 | |
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00194.html | 2017-07-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wesnoth Search vendor "Wesnoth" | Wesnoth Search vendor "Wesnoth" for product "Wesnoth" | 1.2 Search vendor "Wesnoth" for product "Wesnoth" and version "1.2" | - |
Affected
| ||||||
Wesnoth Search vendor "Wesnoth" | Wesnoth Search vendor "Wesnoth" for product "Wesnoth" | 1.2.1 Search vendor "Wesnoth" for product "Wesnoth" and version "1.2.1" | - |
Affected
| ||||||
Wesnoth Search vendor "Wesnoth" | Wesnoth Search vendor "Wesnoth" for product "Wesnoth" | 1.2.2 Search vendor "Wesnoth" for product "Wesnoth" and version "1.2.2" | - |
Affected
| ||||||
Wesnoth Search vendor "Wesnoth" | Wesnoth Search vendor "Wesnoth" for product "Wesnoth" | 1.2.3 Search vendor "Wesnoth" for product "Wesnoth" and version "1.2.3" | - |
Affected
| ||||||
Wesnoth Search vendor "Wesnoth" | Wesnoth Search vendor "Wesnoth" for product "Wesnoth" | 1.2.4 Search vendor "Wesnoth" for product "Wesnoth" and version "1.2.4" | - |
Affected
| ||||||
Wesnoth Search vendor "Wesnoth" | Wesnoth Search vendor "Wesnoth" for product "Wesnoth" | 1.2.5 Search vendor "Wesnoth" for product "Wesnoth" and version "1.2.5" | - |
Affected
| ||||||
Wesnoth Search vendor "Wesnoth" | Wesnoth Search vendor "Wesnoth" for product "Wesnoth" | 1.2.6 Search vendor "Wesnoth" for product "Wesnoth" and version "1.2.6" | - |
Affected
| ||||||
Wesnoth Search vendor "Wesnoth" | Wesnoth Search vendor "Wesnoth" for product "Wesnoth" | 1.3.1 Search vendor "Wesnoth" for product "Wesnoth" and version "1.3.1" | - |
Affected
| ||||||
Wesnoth Search vendor "Wesnoth" | Wesnoth Search vendor "Wesnoth" for product "Wesnoth" | 1.3.2 Search vendor "Wesnoth" for product "Wesnoth" and version "1.3.2" | - |
Affected
| ||||||
Wesnoth Search vendor "Wesnoth" | Wesnoth Search vendor "Wesnoth" for product "Wesnoth" | 1.3.3 Search vendor "Wesnoth" for product "Wesnoth" and version "1.3.3" | - |
Affected
| ||||||
Wesnoth Search vendor "Wesnoth" | Wesnoth Search vendor "Wesnoth" for product "Wesnoth" | 1.3.4 Search vendor "Wesnoth" for product "Wesnoth" and version "1.3.4" | - |
Affected
| ||||||
Wesnoth Search vendor "Wesnoth" | Wesnoth Search vendor "Wesnoth" for product "Wesnoth" | 1.3.5 Search vendor "Wesnoth" for product "Wesnoth" and version "1.3.5" | - |
Affected
| ||||||
Wesnoth Search vendor "Wesnoth" | Wesnoth Search vendor "Wesnoth" for product "Wesnoth" | 1.3.6 Search vendor "Wesnoth" for product "Wesnoth" and version "1.3.6" | - |
Affected
| ||||||
Wesnoth Search vendor "Wesnoth" | Wesnoth Search vendor "Wesnoth" for product "Wesnoth" | 1.3.7 Search vendor "Wesnoth" for product "Wesnoth" and version "1.3.7" | - |
Affected
| ||||||
Wesnoth Search vendor "Wesnoth" | Wesnoth Search vendor "Wesnoth" for product "Wesnoth" | 1.3.8 Search vendor "Wesnoth" for product "Wesnoth" and version "1.3.8" | - |
Affected
|