Valve Software Half-Life Engine Remote Denial of Service Vulnerability
BID:10700
Info
Valve Software Half-Life Engine Remote Denial of Service Vulnerability
| Bugtraq ID: | 10700 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-0724 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Discovery is credited to Terry Henning. |
| Vulnerable: |
Valvesoftware Half-Life Dedicated Server 4.1.1 .1e Win32 Valvesoftware Half-Life Dedicated Server 4.1.1 .1e Linux Valvesoftware Half-Life Dedicated Server 4.1.1 .1d Beta Win32 Valvesoftware Half-Life Dedicated Server 4.1.1 .1c1 Win32 Valvesoftware Half-Life Dedicated Server 4.1.1 .0 Win32 Valvesoftware Half-Life Dedicated Server 4.1 .0.9 Win32 Valvesoftware Half-Life Dedicated Server 4.1 .0.8 Win32 Valvesoftware Half-Life Dedicated Server 4.1 .0.7 Win32 Valvesoftware Half-Life Dedicated Server 4.1 .0.6 Win32 Valvesoftware Half-Life Dedicated Server 4.1 .0.4 Win32 Valvesoftware Half-Life Dedicated Server 3.1.3 Valvesoftware Half-Life Dedicated Server 3.1.1 .1e Win32 Valvesoftware Half-Life Dedicated Server 3.1.1 .1e Linux Valvesoftware Half-Life Dedicated Server 3.1.1 .1d Linux Valvesoftware Half-Life Dedicated Server 3.1.1 .1c1 Linux Valvesoftware Half-Life Dedicated Server 3.1.1 .0 Linux Valvesoftware Half-Life Dedicated Server 3.1 .0.9 Linux Valvesoftware Half-Life Dedicated Server 3.1 .0.8 Linux Valvesoftware Half-Life Dedicated Server 3.1 .0.7 Linux Valvesoftware Half-Life Dedicated Server 3.1 .0.6 Linux Valvesoftware Half-Life Dedicated Server 3.1 .0.5 Linux Valvesoftware Half-Life Dedicated Server 3.1 .0.4 Linux Valvesoftware Half-Life Dedicated Server 3.1 Valvesoftware Half-Life 1.1.1 .0 Valvesoftware Half-Life 1.1 .0.9 Valvesoftware Half-Life 1.1 .0.8 Valvesoftware Half-Life 1.1 .0.4 Windows Valvesoftware Half-Life 1.1 .0.4 Linux |
| Not Vulnerable: | |
Discussion
Valve Software Half-Life Engine Remote Denial of Service Vulnerability
Half-Life is reported prone to a remote denial of service vulnerability. This issue presents itself when the application receives a malformed TCP packet.
All versions of Half-Life released before July 7, 2004 are reported to be vulnerable to this issue.
Half-Life is reported prone to a remote denial of service vulnerability. This issue presents itself when the application receives a malformed TCP packet.
All versions of Half-Life released before July 7, 2004 are reported to be vulnerable to this issue.
Exploit / POC
Valve Software Half-Life Engine Remote Denial of Service Vulnerability
A proof of concept exploit is available from the following location:
http://aluigi.altervista.org/poc/hlboom.zip
A proof of concept exploit is available from the following location:
http://aluigi.altervista.org/poc/hlboom.zip
Solution / Fix
Valve Software Half-Life Engine Remote Denial of Service Vulnerability
Solution:
It is conjectured that versions of Half-Life released after July 7, 2004 are not vulnerable to this issue. This is not confirmed at the moment.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It is conjectured that versions of Half-Life released after July 7, 2004 are not vulnerable to this issue. This is not confirmed at the moment.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Valve Software Half-Life Engine Remote Denial of Service Vulnerability
References:
References: