CVE-2006-4006

Publication date 7 August 2006

Last updated 17 July 2025


Ubuntu priority

Description

The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_pkg function (packets.c) to use this data size when sending a reply, and allows remote attackers to read portions of server memory.

Status

Package Ubuntu Release Status
bomberclone 9.10 karmic
Fixed 0.11.7-1
9.04 jaunty
Fixed 0.11.7-1
8.10 intrepid
Fixed 0.11.7-1
8.04 LTS hardy
Fixed 0.11.7-1
7.10 gutsy
Fixed 0.11.7-1
7.04 feisty
Fixed 0.11.7-1
6.10 edgy
Fixed 0.11.7-1
6.06 LTS dapper Ignored end of life


Access our resources on patching vulnerabilities