Crysis HTTP/XML-RPC Service Access Violation Remote Denial of Service Vulnerability
BID:35735
Info
Crysis HTTP/XML-RPC Service Access Violation Remote Denial of Service Vulnerability
| Bugtraq ID: | 35735 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2009 12:00AM |
| Updated: | Jul 20 2009 09:16PM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
Electronic Arts Inc. Crysis Wars 1.5 Electronic Arts Inc. Crysis 1.21 |
| Not Vulnerable: | |
Discussion
Crysis HTTP/XML-RPC Service Access Violation Remote Denial of Service Vulnerability
Crysis is prone to a remote denial-of-service vulnerability because the application fails to handle exceptional conditions.
An attacker can exploit this issue to crash the affected application, denying further service to legitimate users. Given the nature of this issue, the attacker may also be able to run arbitrary code, but this has not been confirmed.
The following are affected:
Crysis 1.21 and prior versions
Crysis Wars 1.5 and prior versions
Crysis is prone to a remote denial-of-service vulnerability because the application fails to handle exceptional conditions.
An attacker can exploit this issue to crash the affected application, denying further service to legitimate users. Given the nature of this issue, the attacker may also be able to run arbitrary code, but this has not been confirmed.
The following are affected:
Crysis 1.21 and prior versions
Crysis Wars 1.5 and prior versions
Exploit / POC
Crysis HTTP/XML-RPC Service Access Violation Remote Denial of Service Vulnerability
An attacker can exploit this issue by using standard network utilities.
The following command and proof-of-concept HTTP request are available:
nc SERVER HTTPPORT -v -v < crysisviol.txt
An attacker can exploit this issue by using standard network utilities.
The following command and proof-of-concept HTTP request are available:
nc SERVER HTTPPORT -v -v < crysisviol.txt
Solution / Fix
Crysis HTTP/XML-RPC Service Access Violation Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Crysis HTTP/XML-RPC Service Access Violation Remote Denial of Service Vulnerability
References:
References:
- Crysis access violation in the HTTP/XML-RPC service (Luigi Auriemma)
- Crysis Homepage (Crytek)