Call of Duty Remote Denial of Service Vulnerability
BID:11119
Info
Call of Duty Remote Denial of Service Vulnerability
| Bugtraq ID: | 11119 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 06 2004 12:00AM |
| Updated: | Sep 06 2004 12:00AM |
| Credit: | Discovered by Luigi Auriemma <[email protected]>. |
| Vulnerable: |
Activision Call of Duty United Offensive 1.41 Activision Call of Duty 1.4 |
| Not Vulnerable: | |
Discussion
Call of Duty Remote Denial of Service Vulnerability
It has been reported that it is possible for a remote attacker to immediately terminate instances of Call of Duty on target systems. This can be accomplished by sending a large (> 1024 bytes) query or response to the target.
Both the client and server are affected.
Update: It is reported that an expansion pack for Call of Duty named United Offensive has been released. This expansion pack is also vulnerable to this issue.
It has been reported that it is possible for a remote attacker to immediately terminate instances of Call of Duty on target systems. This can be accomplished by sending a large (> 1024 bytes) query or response to the target.
Both the client and server are affected.
Update: It is reported that an expansion pack for Call of Duty named United Offensive has been released. This expansion pack is also vulnerable to this issue.
Exploit / POC
Call of Duty Remote Denial of Service Vulnerability
Proof of concept code has been made available at:
http://aluigi.altervista.org/poc/codboom.zip
Proof of concept code has been made available at:
http://aluigi.altervista.org/poc/codboom.zip
Solution / Fix
Call of Duty Remote Denial of Service Vulnerability
Solution:
A Linux fix is available at:
http://www.icculus.org/betas/cod/
An unofficial third-party Win32 fix has been developed, though it has not been tested by Symantec and is not supported by the vendor. For these reasons, it is not recommended as a valid means of remediation. See the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
A Linux fix is available at:
http://www.icculus.org/betas/cod/
An unofficial third-party Win32 fix has been developed, though it has not been tested by Symantec and is not supported by the vendor. For these reasons, it is not recommended as a valid means of remediation. See the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Call of Duty Remote Denial of Service Vulnerability
References:
References:
- Broadcast shutdown in Call of Duty 1.4 (Luigi Auriemma
) - CoD United Offensive boom boom (Luigi Auriemma
)