Integer overflow in the OggHeaderParse function in Steamcast 0.9.75 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via a long Ogg tag.
Vector
NETWORK
Complexity
LOW
Authentication
NONE
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL
Advisory | Patch | Confirmed | Link |
---|---|---|---|
steamcast-oggheaderparse-dos(39929) | |||
http://aluigi.org/poc/steamcazz.zip | |||
http://aluigi.altervista.org/adv/steamcazz-adv.txt |