CVE-2006-4006

Bomberclone < 0.11.6 - Information Disclosure

Title source: rule

Description

The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_pkg function (packets.c) to use this data size when sending a reply, and allows remote attackers to read portions of server memory.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Luigi Auriemma · cremotelinux
https://www.exploit-db.com/exploits/28314

Scores

EPSS 0.1190
EPSS Percentile 93.8%

Details

CWE
CWE-200
Status published
Products (4)
bomberclone/bomberclone 0.11.3
bomberclone/bomberclone 0.11.4
bomberclone/bomberclone 0.11.5
bomberclone/bomberclone < 0.11.6
Published Aug 07, 2006
Tracked Since Feb 18, 2026