Gentoo Archives: gentoo-announce

From: Stefan Cornelius <dercorny@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200603-11 ] Freeciv: Denial of Service
Date: Thu, 16 Mar 2006 10:17:29
Message-Id: 200603161056.21354.dercorny@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200603-11
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Freeciv: Denial of Service
9 Date: March 16, 2006
10 Bugs: #125304
11 ID: 200603-11
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 A memory allocation bug in Freeciv allows a remote attacker to perform
19 a Denial of Service attack.
20
21 Background
22 ==========
23
24 Freeciv is an open source turn-based multiplayer strategy game, similar
25 to the famous Civilization series.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 games-strategy/freeciv < 2.0.8 >= 2.0.8
34
35 Description
36 ===========
37
38 Luigi Auriemma discovered that Freeciv could be tricked into the
39 allocation of enormous chunks of memory when trying to uncompress
40 malformed data packages, possibly leading to an out of memory condition
41 which causes Freeciv to crash or freeze.
42
43 Impact
44 ======
45
46 A remote attacker could exploit this issue to cause a Denial of Service
47 by sending specially crafted data packages to the Freeciv game server.
48
49 Workaround
50 ==========
51
52 Play solo games or restrict your multiplayer games to trusted parties.
53
54 Resolution
55 ==========
56
57 All Freeciv users should upgrade to the latest version:
58
59 # emerge --sync
60 # emerge --ask --oneshot --verbose ">=games-strategy/freeciv-2.0.8"
61
62 References
63 ==========
64
65 [ 1 ] CVE-2006-0047
66 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0047
67 [ 2 ] Original advisory
68 http://aluigi.altervista.org/adv/freecivdos-adv.txt
69
70 Availability
71 ============
72
73 This GLSA and any updates to it are available for viewing at
74 the Gentoo Security Website:
75
76 http://security.gentoo.org/glsa/glsa-200603-11.xml
77
78 Concerns?
79 =========
80
81 Security is a primary focus of Gentoo Linux and ensuring the
82 confidentiality and security of our users machines is of utmost
83 importance to us. Any security concerns should be addressed to
84 security@g.o or alternatively, you may file a bug at
85 http://bugs.gentoo.org.
86
87 License
88 =======
89
90 Copyright 2006 Gentoo Foundation, Inc; referenced text
91 belongs to its owner(s).
92
93 The contents of this document are licensed under the
94 Creative Commons - Attribution / Share Alike license.
95
96 http://creativecommons.org/licenses/by-sa/2.0