Gentoo Linux Security Advisory GLSA 200802-02 – Luigi Auriemma discovered multiple buffer overflows in the D_NetPlayerEvent() function, the Msg_Write() function and the NetSv_ReadCommands() function. He also discovered errors when handling chat messages that are not NULL-terminated (CVE-2007-4642) or contain a short data length, triggering an integer underflow (CVE-2007-4643). Furthermore a format string vulnerability was discovered in the Cl_GetPackets() function when processing PSV_CONSOLE_TEXT messages (CVE-2007-4644). Versions less than or equal to 1.9.0-beta5.2 are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/63347/glsa-200802-02.txt
Source: https://packetstormsecurity.com/files/63347/Gentoo-Linux-Security-Advisory-200802-2.html

