CVE-2019-12968

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
26/06/2019
Last modified:
02/07/2019

Description

A vulnerability was found in the Sonic Robo Blast 2 (SRB2) plugin (EP_Versions 9 to 11 inclusive) distributed with Doomseeker 1.1 and 1.2. Affected plugin versions did not discard IP packets with an unnaturally long response length from a Sonic Robo Blast 2 master server, allowing a remote attacker to cause a potential crash / denial of service in Doomseeker. The issue has been remediated in the Doomseeker 1.3 release with source code patches to the SRB2 plugin.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:drdteam:doomseeker:1.1:*:*:*:*:*:*:*
cpe:2.3:a:drdteam:doomseeker:1.2:*:*:*:*:*:*:*