CVE-2016-9400
published 2017-02-22CVE-2016-9400: The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical memory…
PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.65%
88.3th percentile
The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical memory locations and possibly execute arbitrary code via vectors involving snap handling.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | teeworlds | < teeworlds 0.6.4+dfsg-1 (bookworm) | teeworlds 0.6.4+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| teeworlds | teeworlds | < 0.6.4 | 0.6.4 |
| teeworlds | teeworlds | >= 0 < 0.6.4+dfsg-1 | 0.6.4+dfsg-1 |
| teeworlds | teeworlds | >= 0 < 0.6.4+dfsg-1 | 0.6.4+dfsg-1 |
| teeworlds | teeworlds | >= 0 < 0.6.4+dfsg-1 | 0.6.4+dfsg-1 |
| teeworlds | teeworlds | >= 0 < 0.6.4+dfsg-1 | 0.6.4+dfsg-1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2016-9400: teeworlds - The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds...
vendor_debian·2016·CVSS 9.8
CVE-2016-9400 [CRITICAL] CVE-2016-9400: teeworlds - The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds...
The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical memory locations and possibly execute arbitrary code via vectors involving snap handling.
Scope: local
bookworm: resolved (fixed in 0.6.4+dfsg-1)
bullseye: resolved (fixed in 0.6.4+dfsg-1)
forky: resolved (fixed in 0.6.4+dfsg-1)
sid: resolved (fixed in 0.6.4+dfsg-1)
trixie: resolved (fixed in 0.6.4+dfsg-1)
GHSA
GHSA-jv4p-f6mv-66w4: The CClient::ProcessServerPacket method in engine/client/client
ghsa_unreviewed·2022-05-13
CVE-2016-9400 [CRITICAL] CWE-119 GHSA-jv4p-f6mv-66w4: The CClient::ProcessServerPacket method in engine/client/client
The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical memory locations and possibly execute arbitrary code via vectors involving snap handling.
OSV
CVE-2016-9400: The CClient::ProcessServerPacket method in engine/client/client
osv·2017-02-22·CVSS 9.8
CVE-2016-9400 [CRITICAL] CVE-2016-9400: The CClient::ProcessServerPacket method in engine/client/client
The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical memory locations and possibly execute arbitrary code via vectors involving snap handling.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9400 teeworlds: Possible remote code execution on teeworlds client
bugzilla·2016-11-18·CVSS 9.8
CVE-2016-9400 [CRITICAL] CVE-2016-9400 teeworlds: Possible remote code execution on teeworlds client
CVE-2016-9400 teeworlds: Possible remote code execution on teeworlds client
A security vulnerabilit was found in teeworlds, there are possible attacker controlled memory-writes and possibly arbitrary code execution on the client, abusable by any server the client joins.
References:
https://www.teeworlds.com/?page=news&id=12086
Upstream patch:
https://github.com/teeworlds/teeworlds/commit/ff254722a2683867fcb3e67569ffd36226c4bc62
Discussion:
Created teeworlds tracking bugs for this issue:
Affects: fedora-all [bug 1396380]
Affects: epel-7 [bug 1396381]
Bugzilla
CVE-2016-9400 teeworlds: Possible remote code execution on teeworlds client [fedora-all]
bugzilla·2016-11-18·CVSS 9.8
CVE-2016-9400 [CRITICAL] CVE-2016-9400 teeworlds: Possible remote code execution on teeworlds client [fedora-all]
CVE-2016-9400 teeworlds: Possible remote code execution on teeworlds client [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2016-9400 teeworlds: Possible remote code execution on teeworlds client [epel-7]
bugzilla·2016-11-18·CVSS 9.8
CVE-2016-9400 [CRITICAL] CVE-2016-9400 teeworlds: Possible remote code execution on teeworlds client [epel-7]
CVE-2016-9400 teeworlds: Possible remote code execution on teeworlds client [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-
http://www.openwall.com/lists/oss-security/2016/11/16/8http://www.openwall.com/lists/oss-security/2016/11/17/8http://www.securityfocus.com/bid/94381https://github.com/teeworlds/teeworlds/commit/ff254722a2683867fcb3e67569ffd36226c4bc62https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C4JNSBXXPE7O32ZMFK7D7YL6EKLG7PRV/https://security.gentoo.org/glsa/201705-13https://www.teeworlds.com/?page=news&id=12086http://www.openwall.com/lists/oss-security/2016/11/16/8http://www.openwall.com/lists/oss-security/2016/11/17/8http://www.securityfocus.com/bid/94381https://github.com/teeworlds/teeworlds/commit/ff254722a2683867fcb3e67569ffd36226c4bc62https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C4JNSBXXPE7O32ZMFK7D7YL6EKLG7PRV/https://security.gentoo.org/glsa/201705-13https://www.teeworlds.com/?page=news&id=12086
2017-02-22
Published