Threat level definition
Search:
Home
Bugtraq
Vulnerabilities
Mailing Lists
Jobs
Tools
Beta Programs
News
Infocus
Foundations
Microsoft
Unix
IDS
Incidents
Virus
Pen-Test
Firewalls
Columnists
Mailing Lists
Newsletters
Bugtraq
Focus on IDS
Focus on Linux
Focus on Microsoft
Forensics
Pen-test
Security Basics
Vuln Dev
Vulnerabilities
Jobs
Job Opportunities
Resumes
Job Seekers
Employers
Tools
RSS
News
Vulns
Security Research
BugTraq
Back to list
|
Post reply
[VSA0305] HLTV remote DoS
Jan 10 2003 05:50PM
VOID.AT Security (crew void at)
[void.at Security Advisory VSA0305]
HLTV offers the ability to have thousands of spectators watch
online games on Half-Life-servers.
Overview
========
By sending a specially crafted packet to the hltv-server,
an attacker can cause the server to crash.
Affected Versions
=================
The one that comes with hlds 3.1.1.0; possibly others.
Impact
======
Medium. The remote server simply crashes.
Details
=======
Packets querying things like player-status etc always start
with \xff\xff\xff\xff, followed by a query command and terminated
by a \0.
When you simply send \xff\xff\xff\xff\0 to the server, it crashes.
Solution
========
Vendor patch needed!
Exploit
=======
Come on :-)
Discovered by
=============
greuff <greuff (at) void (dot) at [email concealed]>
Credits
=======
void.at
everyone who was at 19c3
[ reply ]
Privacy Statement
Copyright 2009, SecurityFocus
HLTV offers the ability to have thousands of spectators watch
online games on Half-Life-servers.
Overview
========
By sending a specially crafted packet to the hltv-server,
an attacker can cause the server to crash.
Affected Versions
=================
The one that comes with hlds 3.1.1.0; possibly others.
Impact
======
Medium. The remote server simply crashes.
Details
=======
Packets querying things like player-status etc always start
with \xff\xff\xff\xff, followed by a query command and terminated
by a \0.
When you simply send \xff\xff\xff\xff\0 to the server, it crashes.
Solution
========
Vendor patch needed!
Exploit
=======
Come on :-)
Discovered by
=============
greuff <greuff (at) void (dot) at [email concealed]>
Credits
=======
void.at
everyone who was at 19c3
[ reply ]