S.T.A.L.K.E.R. Remote Denial of Service Vulnerability
BID:29723
Info
S.T.A.L.K.E.R. Remote Denial of Service Vulnerability
| Bugtraq ID: | 29723 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-6702 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 15 2008 12:00AM |
| Updated: | Jul 23 2009 09:06PM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
GSC Game World S.T.A.L.K.E.R. 1.0 .06 |
| Not Vulnerable: | |
Discussion
S.T.A.L.K.E.R. Remote Denial of Service Vulnerability
S.T.A.L.K.E.R. game servers are prone to a remote denial-of-service vulnerability because the software fails to handle exceptional conditions when processing user nicknames.
Successfully exploiting this issue allows remote attackers to crash the affected application, denying service to legitimate users.
S.T.A.L.K.E.R. game servers are prone to a remote denial-of-service vulnerability because the software fails to handle exceptional conditions when processing user nicknames.
Successfully exploiting this issue allows remote attackers to crash the affected application, denying service to legitimate users.
Exploit / POC
S.T.A.L.K.E.R. Remote Denial of Service Vulnerability
The following proof-of-concept code is available. Symantec has not verified this exploit.
The following proof-of-concept code is available. Symantec has not verified this exploit.
Solution / Fix
S.T.A.L.K.E.R. Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
S.T.A.L.K.E.R. Remote Denial of Service Vulnerability
References:
References:
- STALKER Game World homepage (GSC Game World)
- Denial of Service in S.T.A.L.K.E.R. 1.0006 (Luigi Auriemma
)