CVE-2007-5713
Off-by-one error in the GeoIP module in the AMX Mod X 1.76d plugin for Half-Life Server might allow attackers to execute arbitrary code or cause a denial of service via unspecified input related to geolocation, which triggers an error message from the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.33%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Off-by-one error in the GeoIP module in the AMX Mod X 1.76d plugin for Half-Life Server might allow attackers to execute arbitrary code or cause a denial of service via unspecified input related to geolocation, which triggers an error message from the (1) geoip_code2 or (2) geoip_code3 function, leading to a buffer overflow.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.33% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- amxmodx/amx mod x · valve software/half-life dedicated server
- Source
- cve@mitre.org
References
- http://bugs.alliedmods.net/?do=details&task_id=519
- http://osvdb.org/41980
- http://secunia.com/advisories/27411Patch, Vendor Advisory
- http://wiki.alliedmods.net/AMX_Mod_X_1.8.0_Changes
- http://www.securityfocus.com/bid/26218Patch
- http://bugs.alliedmods.net/?do=details&task_id=519
- http://osvdb.org/41980
- http://secunia.com/advisories/27411Patch, Vendor Advisory
- http://wiki.alliedmods.net/AMX_Mod_X_1.8.0_Changes
- http://www.securityfocus.com/bid/26218Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.