CrossFire Denial Of Service Vulnerability
BID:16883
Info
CrossFire Denial Of Service Vulnerability
| Bugtraq ID: | 16883 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2006-0677 CVE-2006-1010 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2006 12:00AM |
| Updated: | Dec 15 2006 07:58PM |
| Credit: | This issue was disclosed by Luigi Auriemma. |
| Vulnerable: |
Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 Crossfire Crossfire 1.8 |
| Not Vulnerable: |
Crossfire Crossfire 1.9 |
Discussion
CrossFire Denial Of Service Vulnerability
CrossFire is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause the application to crash by activating the 'oldsocketmode' option, and then sending an overly large request to the server application.
An attacker may cause the application to crash, thus denying service to legitimate users; remote code execution may also be possible.
CrossFire is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause the application to crash by activating the 'oldsocketmode' option, and then sending an overly large request to the server application.
An attacker may cause the application to crash, thus denying service to legitimate users; remote code execution may also be possible.
Exploit / POC
CrossFire Denial Of Service Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
CrossFire Denial Of Service Vulnerability
Solution:
The vendor has released version 1.9.0. to address this issue.
Please see the referenced vendor advisories for further information on obtaining and applying fixes.
Crossfire Crossfire 1.8
Solution:
The vendor has released version 1.9.0. to address this issue.
Please see the referenced vendor advisories for further information on obtaining and applying fixes.
Crossfire Crossfire 1.8
-
Crossfire crossfire-server-1.9.0.exe
http://prdownloads.sourceforge.net/crossfire/crossfire-server-1.9.0.ex e
References
CrossFire Denial Of Service Vulnerability
References:
References:
- CrossFire <= 1.8.0 oldsocketmode buffer-overflow 0.1 (Luigi Auriemma)
- Crossfire Homepage (Crossfire)