Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Half-Life StatsMe Plug-in MakeStats Format String Vulnerability

The Half-Life StatsMe plug-in is prone to an exploitable format string vulnerability. This issue may be exploited by an attacker who can authenticate with the rcon-password of the Half-Life server to execute arbitrary code in the context of the server process.

Exploitation may be dependant on which other plug-ins are running on the Half-Life server.

Successful exploitation will allow an attacker to gain local and possibly privileged access to the host running the server.







 

Privacy Statement
Copyright 2009, SecurityFocus