Gearbox Software Halo Game Client Remote Denial Of Service Vulnerability
BID:11724
Info
Gearbox Software Halo Game Client Remote Denial Of Service Vulnerability
| Bugtraq ID: | 11724 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 22 2004 12:00AM |
| Updated: | Nov 22 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Luigi Auriemma <[email protected]>. |
| Vulnerable: |
Gearbox Software Halo Combat Evolved 1.31 Gearbox Software Halo Combat Evolved 1.5 Gearbox Software Halo Combat Evolved 1.4 Gearbox Software Halo Combat Evolved 1.2 |
| Not Vulnerable: |
Gearbox Software Halo Combat Evolved 1.06 |
Discussion
Gearbox Software Halo Game Client Remote Denial Of Service Vulnerability
The Halo game client is reported prone to a remote denial of service vulnerability. It is reported that when using the in game browser to view a server list, a malicious reply from a server may crash the affected client.
A remote attacker may exploit this vulnerability to deny service to legitimate users.
The Halo game client is reported prone to a remote denial of service vulnerability. It is reported that when using the in game browser to view a server list, a malicious reply from a server may crash the affected client.
A remote attacker may exploit this vulnerability to deny service to legitimate users.
Exploit / POC
Gearbox Software Halo Game Client Remote Denial Of Service Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Gearbox Software Halo Game Client Remote Denial Of Service Vulnerability
Solution:
It is reported that this vulnerability is addressed in Halo: Combat Evolved version 1.06, this however is not confirmed. Customers are advised to contact the vendor for further information in regards to obtaining and applying an appropriate patch.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It is reported that this vulnerability is addressed in Halo: Combat Evolved version 1.06, this however is not confirmed. Customers are advised to contact the vendor for further information in regards to obtaining and applying an appropriate patch.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Gearbox Software Halo Game Client Remote Denial Of Service Vulnerability
References:
References:
- Halo Combat Evolved For Windows (Microsoft)
- Broadcast client crash in Halo 1.05 (Luigi Auriemma
)