Roger Wilco Base Station Denial of Service Vulnerability
BID:8078
Info
Roger Wilco Base Station Denial of Service Vulnerability
| Bugtraq ID: | 8078 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2003 12:00AM |
| Updated: | Jul 02 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Auriemma Luigi <[email protected]>. |
| Vulnerable: |
GameSpy RW Base Station 0.3 0a GameSpy Roger Wilco Graphical Server 1.4.1 .6 |
| Not Vulnerable: | |
Discussion
Roger Wilco Base Station Denial of Service Vulnerability
A vulnerability has been reported for the Roger Wilco Base Station. The problem occurs when the server attempts to process incomplete client requests. As a result, it may be possible to indefinitely block a server into a function call while the attacker maintains a connection.
This could be exploited to deny Roger Wilco services to other legitimate users.
It has been reported that the Roger Wilco 1.4.1.6 Graphical Server is also affected by this vulnerability.
A vulnerability has been reported for the Roger Wilco Base Station. The problem occurs when the server attempts to process incomplete client requests. As a result, it may be possible to indefinitely block a server into a function call while the attacker maintains a connection.
This could be exploited to deny Roger Wilco services to other legitimate users.
It has been reported that the Roger Wilco 1.4.1.6 Graphical Server is also affected by this vulnerability.
Exploit / POC
Roger Wilco Base Station Denial of Service Vulnerability
Luigi Auriemma <[email protected]> has supplied a proof of concept exploit 'wilco.zip' available at the following location:
http://www.zone-h.org/download/file=5019/
Luigi Auriemma <[email protected]> has supplied a proof of concept exploit 'wilco.zip' available at the following location:
http://www.zone-h.org/download/file=5019/
Solution / Fix
Roger Wilco Base Station Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.