CVE-2007-4508 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 6% (pctl 93)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in Rebellion Asura engine, as used for the server in Rogue Trooper 1.0 and earlier and Prism 1.1.1.0 and earlier, allows remote attackers to execute arbitrary code via a long string in a 0xf007 packet for the challenge B query.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 6.02% — more likely to be exploited than 93% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-08-23 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| rebellion | rogue trooper |
| rival interactive | prism |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Asura Engine Challenge B Query - Remote Stack Buffer Overflow | 2007-08-22 |
References
- http://aluigi.altervista.org/adv/asurabof-adv.txt
- http://osvdb.org/39799
- http://secunia.com/advisories/24023
- http://secunia.com/advisories/26571
- http://securityreason.com/securityalert/3053
- http://www.securityfocus.com/archive/1/477357/100/0/threaded
- http://www.securityfocus.com/bid/25411
- http://www.vupen.com/english/advisories/2007/2955
- http://www.vupen.com/english/advisories/2007/2956
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36221
- http://aluigi.altervista.org/adv/asurabof-adv.txt
- http://osvdb.org/39799
- http://secunia.com/advisories/24023
- http://secunia.com/advisories/26571
- http://securityreason.com/securityalert/3053
- http://www.securityfocus.com/archive/1/477357/100/0/threaded
- http://www.securityfocus.com/bid/25411
- http://www.vupen.com/english/advisories/2007/2955
- http://www.vupen.com/english/advisories/2007/2956
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36221
→ the Explorer · watch your stack · NVD