Valve Software Half-Life Client Connection Routine Buffer Overflow Vulnerability
BID:8299
Info
Valve Software Half-Life Client Connection Routine Buffer Overflow Vulnerability
| Bugtraq ID: | 8299 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 29 2003 12:00AM |
| Updated: | Jul 29 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Auriemma Luigi <[email protected]>. |
| Vulnerable: |
Valve Software Half-Life 1.1.1 .0 Valve Software Half-Life 1.1 .0.9 Valve Software Half-Life 1.1 .0.8 |
| Not Vulnerable: | |
Discussion
Valve Software Half-Life Client Connection Routine Buffer Overflow Vulnerability
Half-Life Client has been reported prone to a remotely exploitable buffer overflow condition.
The issue presents itself in the client connection routine, used by the client to negotiate a connection to the Half-Life game server. Due to a lack of sufficient bounds checking performed on both the parameter and value of data transmitted from the game server to the client, a malicious server may execute arbitrary code on an affected client.
Half-Life Client has been reported prone to a remotely exploitable buffer overflow condition.
The issue presents itself in the client connection routine, used by the client to negotiate a connection to the Half-Life game server. Due to a lack of sufficient bounds checking performed on both the parameter and value of data transmitted from the game server to the client, a malicious server may execute arbitrary code on an affected client.
Exploit / POC
Valve Software Half-Life Client Connection Routine Buffer Overflow Vulnerability
The following proofs of concept has been supplied:
The following proofs of concept has been supplied:
Solution / Fix
References
Valve Software Half-Life Client Connection Routine Buffer Overflow Vulnerability
References:
References:
- Valve Software Homepage (Valve Software)
- Half-Life clients: buffer-overflow (Auriemma Luigi
)