PunkBuster Module Remote Format String Vulnerability
BID:16703
Info
PunkBuster Module Remote Format String Vulnerability
| Bugtraq ID: | 16703 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 16 2006 12:00AM |
| Updated: | Feb 17 2006 06:42PM |
| Credit: | Luigi Auriemma is credited with the discovery of this vulnerability. |
| Vulnerable: |
Raven Software Soldier Of Fortune 2 1.0 3 Raven Software Soldier Of Fortune 2 1.0 2 |
| Not Vulnerable: | |
Discussion
PunkBuster Module Remote Format String Vulnerability
A remote format-string vulnerability affects PunkBuster. The module fails to properly sanitize user-supplied input data before using it in a formatted-printing function.
A remote attacker may leverage this issue to execute arbitrary code with the privileges of the user running the affected application.
This issue has been confirmed in Soldier of Fortune II; that game uses the PunkBuster module.
A remote format-string vulnerability affects PunkBuster. The module fails to properly sanitize user-supplied input data before using it in a formatted-printing function.
A remote attacker may leverage this issue to execute arbitrary code with the privileges of the user running the affected application.
This issue has been confirmed in Soldier of Fortune II; that game uses the PunkBuster module.
Exploit / POC
PunkBuster Module Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:vuldb@securityfocus.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:vuldb@securityfocus.
Solution / Fix
PunkBuster Module Remote Format String Vulnerability
Solution:
Reports indicate updates correcting this issue may be available; Symantec has not confirmed this. Users are advised to contact the vendor for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Reports indicate updates correcting this issue may be available; Symantec has not confirmed this. Users are advised to contact the vendor for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
PunkBuster Module Remote Format String Vulnerability
References:
References:
- Product Home Page (PunkBuster)
- Raven Software Homepage (Raven Software)
- Soldier Of Fortune Homepage (Raven Software)
- Soldier of Fortune II with PunkBuster enabled (Luigi Auriemma)