AMX Mod Remote 'amx_say' Format String Vulnerability
BID:6968
Info
AMX Mod Remote 'amx_say' Format String Vulnerability
| Bugtraq ID: | 6968 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2003 12:00AM |
| Updated: | Feb 26 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to greuff <[email protected]>. |
| Vulnerable: |
AMX Mod AMX Mod 0.9.2 |
| Not Vulnerable: | |
Discussion
AMX Mod Remote 'amx_say' Format String Vulnerability
A format string vulnerability has been discovered AMX Mod 0.9.2 and earlier which may be exploitable to execute arbitrary code on a target Half-Life server. The problem occurs when calling the 'amx_say' command. By passing specially constructed format specifiers as an argument to the command, it is possible to modify arbitrary locations in memory.
It should be noted that rcon authentication is required to access the 'amx_say' command.
A format string vulnerability has been discovered AMX Mod 0.9.2 and earlier which may be exploitable to execute arbitrary code on a target Half-Life server. The problem occurs when calling the 'amx_say' command. By passing specially constructed format specifiers as an argument to the command, it is possible to modify arbitrary locations in memory.
It should be noted that rcon authentication is required to access the 'amx_say' command.
Exploit / POC
AMX Mod Remote 'amx_say' Format String Vulnerability
An exploit has been made available by void.at:
An exploit has been made available by void.at:
Solution / Fix
AMX Mod Remote 'amx_say' Format String Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
AMX Mod Remote 'amx_say' Format String Vulnerability
References:
References:
- AMX Mod Homepage (AMX Mod)
- [VSA0308] Half-Life AMX-Mod remote (root) hole ("VOID.AT Security"
)