CVE-2011-10020 Details
Description
Kaillera Server version 0.86 is vulnerable to a denial-of-service condition triggered by sending a malformed UDP packet after the initial handshake. Once a client sends a valid HELLO0.83 packet and receives a response, any subsequent malformed packet causes the server to crash and become unresponsive. This flaw stems from improper input validation in the server’s UDP packet handler, allowing unauthenticated remote attackers to disrupt service availability.
A denial-of-service vulnerability has been identified in Kaillera Server version 0.86. The issue arises from improper input validation in the server's UDP packet handler, allowing unauthenticated remote attackers to send malformed UDP packets that disrupt the server's availability. The vulnerability is triggered after a client has completed the initial handshake by sending a valid HELLO0.83 packet. Once this handshake is established, any subsequent malformed packet causes the server to crash and become unresponsive.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 20, 2025CISA-ADP
Assessed Aug 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Kaillera Server | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Aug 22, 2025 | CVE Modified | CISA-ADP |
| Aug 20, 2025 | New CVE Received | [email protected] |
Volerion