VulnerabilityModified
CVE-2006-2411
Buffer overflow in raydium_network_read function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to execute arbitrary code by sending packets with long global variables to the client.
HIGH 7.5EPSS 5.61%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in raydium_network_read function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to execute arbitrary code by sending packets with long global variables to the client.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 5.61% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- raydium/raydium
- Source
- cve@mitre.org
References
- http://aluigi.altervista.org/adv/raydiumx-adv.txtVendor Advisory
- http://secunia.com/advisories/20097Vendor Advisory
- http://securityreason.com/securityalert/900
- http://www.securityfocus.com/archive/1/433930/100/0/threaded
- http://www.securityfocus.com/bid/17986
- http://www.vupen.com/english/advisories/2006/1808
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26516
- http://aluigi.altervista.org/adv/raydiumx-adv.txtVendor Advisory
- http://secunia.com/advisories/20097Vendor Advisory
- http://securityreason.com/securityalert/900
- http://www.securityfocus.com/archive/1/433930/100/0/threaded
- http://www.securityfocus.com/bid/17986
- http://www.vupen.com/english/advisories/2006/1808
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26516
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.