SeriousSam SeriousEngine User Management Remote Denial Of Service Vulnerability
BID:11279
Info
SeriousSam SeriousEngine User Management Remote Denial Of Service Vulnerability
| Bugtraq ID: | 11279 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 2004 12:00AM |
| Updated: | Sep 29 2004 12:00AM |
| Credit: | Luigi Auriemma <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
SeriousSam SeriousEngine |
| Not Vulnerable: | |
Discussion
SeriousSam SeriousEngine User Management Remote Denial Of Service Vulnerability
It is reported that the SeriousSam SeriousEngine is susceptible to a remote denial of service venerability. This issue is due to a failure of the game server software to handle many simultaneous connections.
This vulnerability allows remote attackers to crash the affected application, denying service to legitimate users.
It should be noted that this issue was previously classified as affecting the Alpha Black Zero game application solely. Information has been released implicating the underlying game engine; the BID has been updated accordingly.
It is reported that the SeriousSam SeriousEngine is susceptible to a remote denial of service venerability. This issue is due to a failure of the game server software to handle many simultaneous connections.
This vulnerability allows remote attackers to crash the affected application, denying service to legitimate users.
It should be noted that this issue was previously classified as affecting the Alpha Black Zero game application solely. Information has been released implicating the underlying game engine; the BID has been updated accordingly.
Exploit / POC
SeriousSam SeriousEngine User Management Remote Denial Of Service Vulnerability
A proof of concept exploit was provided:
A proof of concept exploit was provided:
Solution / Fix
SeriousSam SeriousEngine User Management Remote Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SeriousSam SeriousEngine User Management Remote Denial Of Service Vulnerability
References:
References:
- Alpha Black Zero Home Page (Playlogic International)
- SeriousEngine Home Page (SeriousEngine.com)
- Crash in Alpha Black Zero 1.04 (Luigi Auriemma
) - Players overflow in Serious engine UDP (was Alpha Black Zero, 29 Sep 2004) (Luigi Auriemma
)