Monolith Lithtech Game Engine Multiple Remote Format String Vulnerabilities
BID:11610
Info
Monolith Lithtech Game Engine Multiple Remote Format String Vulnerabilities
| Bugtraq ID: | 11610 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-1500 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 05 2004 12:00AM |
| Updated: | Oct 01 2007 10:59PM |
| Credit: | Discovery of these issues is credited to Luigi Auriemma <[email protected]>. |
| Vulnerable: |
Monolith Productions Tron 2.0 1.42 Monolith Productions Shogo 2.2 Monolith Productions Sanity 1.0 Monolith Productions Purge Jihad 2.2.1 Monolith Productions No One Lives Forever 2 1.3 Monolith Productions No One Lives Forever 1.0 .004 Monolith Productions Legends of Might and Magic 1.1 Monolith Productions Kiss Psycho Circus 1.13 Monolith Productions Global Operations 2.1 Monolith Productions Global Operations 2.0 Monolith Productions F.E.A.R. 1.0 2 Monolith Productions F.E.A.R. 1.0 1 Monolith Productions F.E.A.R. 1.08 Monolith Productions Contract Jack 1.1 Monolith Productions Blood 2 2.1 Monolith Productions Alien versus Predator 2 1.0.9 .6 |
| Not Vulnerable: |
Monolith Productions Purge Jihad 2.2.2 |
Discussion
Monolith Lithtech Game Engine Multiple Remote Format String Vulnerabilities
Lithtech game engine is prone to multiple remote format-string vulnerabilities because of incorrect usage of 'printf()'-type functions. Format specifiers can be supplied directly to vulnerable functions from external data.
A denial-of-service condition arises when a vulnerable server handles a malformed request.
Exploiting these issues may also allow an attacker to write to arbitrary process memory and potentially execute code. Any code executed through this vulnerability could potentially run with the privileges of the server.
Lithtech game engine is prone to multiple remote format-string vulnerabilities because of incorrect usage of 'printf()'-type functions. Format specifiers can be supplied directly to vulnerable functions from external data.
A denial-of-service condition arises when a vulnerable server handles a malformed request.
Exploiting these issues may also allow an attacker to write to arbitrary process memory and potentially execute code. Any code executed through this vulnerability could potentially run with the privileges of the server.
Exploit / POC
Monolith Lithtech Game Engine Multiple Remote Format String Vulnerabilities
The following proof-of-concept exploit is available:
The following proof-of-concept exploit is available:
Solution / Fix
Monolith Lithtech Game Engine Multiple Remote Format String Vulnerabilities
Solution:
Reportedly, Purge Jihad 2.2.2 address this vulnerability. Please contact the vendor for more information.
Solution:
Reportedly, Purge Jihad 2.2.2 address this vulnerability. Please contact the vendor for more information.
References
Monolith Lithtech Game Engine Multiple Remote Format String Vulnerabilities
References:
References:
- Monolith Productions Home Page (Monolith Productions)
- Format string in F.E.A.R. 1.08 through PB (Luigi Auriemma)
- In-game format string bug in the Lithtech engine (Luigi Auriemma
)