CVE-2006-1194

ENet < Jul 2005 - DoS

Title source: llm

Description

Integer signedness error in the enet_protocol_handle_incoming_commands function in protocol.c for ENet library CVS version Jul 2005 and earlier, as used in products including (1) Cube, (2) Sauerbraten, and (3) Duke3d_w32, allows remote attackers to cause a denial of service (application crash) via a packet with a large command length value, which leads to an invalid memory access.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Luigi Auriemma · cdosmultiple
https://www.exploit-db.com/exploits/27420

Scores

EPSS 0.1595
EPSS Percentile 94.8%

Details

Status published
Products (1)
enet/enet_library < jul_2005
Published Mar 13, 2006
Tracked Since Feb 18, 2026