CVE-2019-12968

MEDIUM

Doomseeker 1.1-1.2 - Denial of Service via SRB2 Plugin IP Packet Length Handling

Title source: llm
STIX 2.1

Description

A vulnerability was found in the Sonic Robo Blast 2 (SRB2) plugin (EP_Versions 9 to 11 inclusive) distributed with Doomseeker 1.1 and 1.2. Affected plugin versions did not discard IP packets with an unnaturally long response length from a Sonic Robo Blast 2 master server, allowing a remote attacker to cause a potential crash / denial of service in Doomseeker. The issue has been remediated in the Doomseeker 1.3 release with source code patches to the SRB2 plugin.

Scores

CVSS v3 5.3
EPSS 0.0104
EPSS Percentile 77.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-119
Status published
Products (2)
drdteam/doomseeker 1.1
drdteam/doomseeker 1.2
Published Jun 26, 2019
Tracked Since Feb 18, 2026