Unrated severityNVD Advisory· Published Aug 9, 2006· Updated Apr 16, 2026
CVE-2006-4024
CVE-2006-4024
Description
The FESTAHES_Load function in pce/hes.c in Festalon 0.5.0 through 0.5.5 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative LoadAddr value in a HES file, which is used as an offset in a memcpy operation and leads to a buffer underflow.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- aluigi.altervista.org/adv/festahc-adv.txtnvdExploitVendor Advisory
- secunia.com/advisories/21367nvdVendor Advisory
- www.securityfocus.com/bid/19402nvd
- www.vupen.com/english/advisories/2006/3177nvd
News mentions
0No linked articles in our index yet.