CVE-2006-4006
Bomberclone < 0.11.6 - Information Disclosure
Title source: ruleDescription
The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_pkg function (packets.c) to use this data size when sending a reply, and allows remote attackers to read portions of server memory.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Luigi Auriemma · cremotelinux
https://www.exploit-db.com/exploits/28314
References (9)
Scores
EPSS
0.1190
EPSS Percentile
93.8%
Details
CWE
CWE-200
Status
published
Products (4)
bomberclone/bomberclone
0.11.3
bomberclone/bomberclone
0.11.4
bomberclone/bomberclone
0.11.5
bomberclone/bomberclone
< 0.11.6
Published
Aug 07, 2006
Tracked Since
Feb 18, 2026