aluigi.altervista.org
http://aluigi.altervista.org/adv/xprallyboom-adv.txt CVE-2005-0325
Xpand Rally 1.0.0.0 (Server/Clients) - Crash
Record summary
CVE-2005-0325 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Xpand Rally 1.0.0.0 allows remote attackers or remote malicious game servers to cause a denial of service (application crash) via a packet with large values that are not properly handled in certain malloc or memcpy operations.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBXpand Rally 1.0.0.0 (Server/Clients) - CrashExploitDB exploitby Luigi AuriemmaNot analyzed1 file
References
820050130 Broadcast crash in Xpand Rally 1.0.0.0mailing list
http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031336.html 20050130 Broadcast crash in Xpand Rally 1.0.0.0mailing list
http://marc.info/?l=bugtraq&m=110720064811485&w=2 14073Third-party advisory
http://secunia.com/advisories/14073 1013043vdb entry
http://securitytracker.com/id?1013043 12409vdb entry
http://www.securityfocus.com/bid/12409 xpand-rally-memory-dos(19150)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/19150 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-0325