CVE-2020-9005

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
17/02/2020
Last modified:
07/02/2022

Description

meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gaming server with a crafted map, and inviting a victim to this server. A GetValue call is mishandled.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:valvesoftware:dota_2:*:*:*:*:*:*:*:* 2020-02-17 (including)


References to Advisories, Solutions, and Tools