Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2007-3917

Published: 11 October 2007

The multiplayer engine in Wesnoth 1.2.x before 1.2.7 and 1.3.x before 1.3.9 allows remote servers to cause a denial of service (crash) via a long message with multibyte characters that can produce an invalid UTF-8 string after it is truncated, which triggers an uncaught exception, involving the truncate_message function in server/server.cpp. NOTE: this issue affects both clients and servers.

Priority

Low

Status

Package Release Status
wesnoth
Launchpad, Ubuntu, Debian
dapper
Released (1.1+reverted+to+1.0.2-0ubuntu1.2)
edgy
Released (1.1.8-1ubuntu0.2)
feisty
Released (1.2.3-0ubuntu1.1)
gutsy
Released (1.2.6-1ubuntu2.1)
upstream
Released (1.2.7)