Description
Integer signedness error in the enet_protocol_handle_incoming_commands function in protocol.c for ENet library CVS version Jul 2005 and earlier, as used in products including (1) Cube, (2) Sauerbraten, and (3) Duke3d_w32, allows remote attackers to cause a denial of service (application crash) via a packet with a large command length value, which leads to an invalid memory access.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T17:03:28.500Z
Reserved: 2006-03-13T00:00:00.000Z
Link: CVE-2006-1194
No data.
Status : Modified
Published: 2006-03-13T22:02:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2006-1194
No data.
OpenCVE Enrichment
No data.
Weaknesses