CVE Vulnerabilities

CVE-2006-1840

Use of Externally-Controlled Format String

Published: Apr 19, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple format string vulnerabilities in Empire Server before 4.3.1 allow attackers to cause a denial of service (crash) via the (1) load, (2) spy and (3) bomb functions.

Weakness

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Affected Software

Name Vendor Start Version End Version
Empire_server Empire_server * 4.3.0 (including)
Empire_server Empire_server 4.2.10 (including) 4.2.10 (including)
Empire_server Empire_server 4.2.11 (including) 4.2.11 (including)
Empire_server Empire_server 4.2.12 (including) 4.2.12 (including)
Empire_server Empire_server 4.2.13 (including) 4.2.13 (including)
Empire_server Empire_server 4.2.14 (including) 4.2.14 (including)
Empire_server Empire_server 4.2.15 (including) 4.2.15 (including)
Empire_server Empire_server 4.2.16 (including) 4.2.16 (including)
Empire_server Empire_server 4.2.17 (including) 4.2.17 (including)
Empire_server Empire_server 4.2.18 (including) 4.2.18 (including)
Empire_server Empire_server 4.2.19 (including) 4.2.19 (including)
Empire_server Empire_server 4.2.20 (including) 4.2.20 (including)
Empire_server Empire_server 4.2.21 (including) 4.2.21 (including)
Empire_server Empire_server 4.2.22 (including) 4.2.22 (including)
Empire_server Empire_server 4.2.23 (including) 4.2.23 (including)

Potential Mitigations

References