Gamespy Software Development Kit CD-Key Validation Buffer Overflow Vulnerability
BID:11881
Info
Gamespy Software Development Kit CD-Key Validation Buffer Overflow Vulnerability
| Bugtraq ID: | 11881 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 2004 12:00AM |
| Updated: | Dec 10 2004 12:00AM |
| Credit: | Luigi Auriemma <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
GameSpy Software Development Kit |
| Not Vulnerable: | |
Discussion
Gamespy Software Development Kit CD-Key Validation Buffer Overflow Vulnerability
It has been reported that the GameSpy SDK is prone to a buffer overflow vulnerability in its CD-key validation functionality. This issue is due to a failure of the SDK to properly check the length of user-supplied network data prior to copying it to a fixed-sized memory buffer.
Exploitation of this issue may allow attackers to execute arbitrary machine code in the context of the affected GameSpy developed game.
It has been reported that the GameSpy SDK is prone to a buffer overflow vulnerability in its CD-key validation functionality. This issue is due to a failure of the SDK to properly check the length of user-supplied network data prior to copying it to a fixed-sized memory buffer.
Exploitation of this issue may allow attackers to execute arbitrary machine code in the context of the affected GameSpy developed game.
Exploit / POC
Gamespy Software Development Kit CD-Key Validation Buffer Overflow Vulnerability
A proof of concept exploit is provided:
A proof of concept exploit is provided:
Solution / Fix
Gamespy Software Development Kit CD-Key Validation Buffer Overflow Vulnerability
Solution:
It is reported that the affected SDK has been fixed 19 November 2004, but this has not been confirmed by the vendor. Individual games utilizing the SDK also have to be fixed, and Symantec is currently unaware of vendor-supplied patches. This BID will be updated as further information is disclosed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It is reported that the affected SDK has been fixed 19 November 2004, but this has not been confirmed by the vendor. Individual games utilizing the SDK also have to be fixed, and Symantec is currently unaware of vendor-supplied patches. This BID will be updated as further information is disclosed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Gamespy Software Development Kit CD-Key Validation Buffer Overflow Vulnerability
References:
References:
- Vendor Home Page (GameSpy)
- In-game buffer-overflow in the Gamespy cd-key validation SDK (Luigi Auriemma
)