Half-Life Client Side Connect Buffer Overflow Vulnerability
BID:3353
Info
Half-Life Client Side Connect Buffer Overflow Vulnerability
| Bugtraq ID: | 3353 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 20 2001 12:00AM |
| Updated: | Mar 19 2015 08:25AM |
| Credit: | This vulnerability was announced by Stanley G. Bubrouski <[email protected]> via Bugtraq on September 20, 2001. |
| Vulnerable: |
Valvesoftware Half-Life 1.1 .0.8 |
| Not Vulnerable: | |
Discussion
Half-Life Client Side Connect Buffer Overflow Vulnerability
Half-Life is a popular game distributed and maintained by Valve Software. It includes features that allow users to game locally, or in distributed network environments.
A buffer overflow has been discovered in the Half-Life client that could allow the execution of arbitrary code. When the /Connect command is supplied with an argument of 128 bytes of data, a buffer overflow occurs. This is compounded by the fact that utilities such as Admin-Mod can execute the /Connect command locally on clients.
This could allow a malicious Half-Life server to execute arbitrary code, and potentially give access to a system with the privileges of the user of the Half-Life client.
Half-Life is a popular game distributed and maintained by Valve Software. It includes features that allow users to game locally, or in distributed network environments.
A buffer overflow has been discovered in the Half-Life client that could allow the execution of arbitrary code. When the /Connect command is supplied with an argument of 128 bytes of data, a buffer overflow occurs. This is compounded by the fact that utilities such as Admin-Mod can execute the /Connect command locally on clients.
This could allow a malicious Half-Life server to execute arbitrary code, and potentially give access to a system with the privileges of the user of the Half-Life client.
Exploit / POC
Half-Life Client Side Connect Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Half-Life Client Side Connect Buffer Overflow Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Half-Life Client Side Connect Buffer Overflow Vulnerability
References:
References: