VYPR
Unrated severityNVD Advisory· Published Aug 7, 2006· Updated Apr 16, 2026

CVE-2006-4006

CVE-2006-4006

Description

The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_pkg function (packets.c) to use this data size when sending a reply, and allows remote attackers to read portions of server memory.

Affected products

4
  • cpe:2.3:a:bomberclone:bomberclone:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:bomberclone:bomberclone:*:*:*:*:*:*:*:*range: <=0.11.6
    • cpe:2.3:a:bomberclone:bomberclone:0.11.3:*:*:*:*:*:*:*
    • cpe:2.3:a:bomberclone:bomberclone:0.11.4:*:*:*:*:*:*:*
    • cpe:2.3:a:bomberclone:bomberclone:0.11.5:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.