Security Advisory

CVE-2025-58447

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-09-09 22:11:03
Last updated 2025-09-10 19:30:07
Assigner GitHub_M
State PUBLISHED

Description

rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 2f5248b have a heap-based buffer overflow in the login server, remote attacker to overwrite adjacent session fields by sending a crafted `CA_SSO_LOGIN_REQ` with an oversized token length. This leads to immediate denial of service (crash) and it is possible to achieve remote code execution via heap corruption. Commit 2f5248b fixes the issue.