ToCA Race Driver Multiple Remote Format String And Buffer Overflow Vulnerabilities
BID:14304
Info
ToCA Race Driver Multiple Remote Format String And Buffer Overflow Vulnerabilities
| Bugtraq ID: | 14304 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2005 12:00AM |
| Updated: | Jul 18 2005 12:00AM |
| Credit: | Luigi Auriemma <[email protected]> discovered these issues. |
| Vulnerable: |
ToCA Race Driver 1.2 0 ToCA Race Driver |
| Not Vulnerable: | |
Discussion
ToCA Race Driver Multiple Remote Format String And Buffer Overflow Vulnerabilities
ToCA Race Driver is susceptible to multiple remote buffer overflow and format string vulnerabilities. These issues both stem from the improper use of the 'sprintf()' function.
The game utilizes 'sprintf()' to build strings for visualizing text data for the player. The incorrect usage of this function is exploitable in the public chat, and in the in-game server browser. Other locations may also be affected.
These vulnerabilities allow remote attackers to execute arbitrary machine code in the context of affected client applications. This may occur in either a broadcast, or unicast fashion.
ToCA Race Driver is susceptible to multiple remote buffer overflow and format string vulnerabilities. These issues both stem from the improper use of the 'sprintf()' function.
The game utilizes 'sprintf()' to build strings for visualizing text data for the player. The incorrect usage of this function is exploitable in the public chat, and in the in-game server browser. Other locations may also be affected.
These vulnerabilities allow remote attackers to execute arbitrary machine code in the context of affected client applications. This may occur in either a broadcast, or unicast fashion.
Exploit / POC
ToCA Race Driver Multiple Remote Format String And Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
By using '%n%n%n' as a server name, nickname, or a chat message, this vulnerability will be demonstrated by crashing affected clients.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
By using '%n%n%n' as a server name, nickname, or a chat message, this vulnerability will be demonstrated by crashing affected clients.
Solution / Fix
ToCA Race Driver Multiple Remote Format String And Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
ToCA Race Driver Multiple Remote Format String And Buffer Overflow Vulnerabilities
References:
References:
- Race Driver Home Page (ToCA)
- Broadcast format string and buffer-overflow in Race Driver 1.20 (Luigi Auriemma
)