CVE-2005-0906

Tincat 2.x < 2.0.28 - Buffer Overflow in Player Logging Function

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-0906. PoCs published by Luigi Auriemma.

AI-analyzed exploit summary The provided text describes a remote buffer overflow vulnerability in Tincat's logging function, which could allow unauthorized access. However, no actual exploit code is included, only a reference to a binary exploit.

Description

Buffer overflow in a player logging function in the Tincat network library 2.x before 2.0.28, as used in games such as Sacred and The Settlers: Heritage of Kings, allows remote attackers to execute arbitrary code.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Luigi Auriemma · textremotemultiple
https://www.exploit-db.com/exploits/25291

The provided text describes a remote buffer overflow vulnerability in Tincat's logging function, which could allow unauthorized access. However, no actual exploit code is included, only a reference to a binary exploit.

Classification
Writeup 80%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Tincat (version unspecified)
No auth needed
Prerequisites: Network access to the vulnerable Tincat server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/14762
Exploit mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/394404
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/14767
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/12912

Scores

EPSS 0.0492
EPSS Percentile 91.0%

Details

Status published
Products (3)
instance_four/tincat release_2
sacred/sacred 1.8.2.6
ubi_soft/the_settlersheritage_of_kings 1.0_2
Published May 02, 2005
Tracked Since Feb 18, 2026