Roger Wilco Remote Server Side Buffer Overrun Vulnerability
BID:8566
Info
Roger Wilco Remote Server Side Buffer Overrun Vulnerability
| Bugtraq ID: | 8566 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 08 2003 12:00AM |
| Updated: | Sep 08 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Luigi Auriemma <[email protected]>. |
| Vulnerable: |
GameSpy Roger Wilco Graphical Server 1.4.1 .6 GameSpy Roger Wilco Graphical Server 1.4.1 .5 GameSpy Roger Wilco Graphical Server 1.4.1 .4 GameSpy Roger Wilco Graphical Server 1.4.1 .3 GameSpy Roger Wilco Graphical Server 1.4.1 .2 GameSpy Roger Wilco Graphical Server 1.4.1 .1 GameSpy Roger Wilco Dedicated Server (Win32) 0.30 a GameSpy Roger Wilco Dedicated Server (Win32) 0.29 GameSpy Roger Wilco Dedicated Server (Win32) 0.28 GameSpy Roger Wilco Dedicated Server (Win32) 0.27 GameSpy Roger Wilco Dedicated Server (Win32) 0.26 GameSpy Roger Wilco Dedicated Server (Linux,BSD) 0.27 GameSpy Roger Wilco Dedicated Server (Linux,BSD) 0.26 |
| Not Vulnerable: | |
Discussion
Roger Wilco Remote Server Side Buffer Overrun Vulnerability
A vulnerability has been reported for various Roger Wilco server releases. The problem occurs server-side, and can be triggered when processing malformed client packets. Specifically, when connecting to a server the Roger Wilco client transmits a packet containing the size of data to be copied into an internal buffer. As a result, a malicious user could modify the size to result in excessive data being copied into a previously allocated buffer. This could ultimately allow for sensitive server memory to be corrupted, potentially resulting in the execution of arbitrary code.
A vulnerability has been reported for various Roger Wilco server releases. The problem occurs server-side, and can be triggered when processing malformed client packets. Specifically, when connecting to a server the Roger Wilco client transmits a packet containing the size of data to be copied into an internal buffer. As a result, a malicious user could modify the size to result in excessive data being copied into a previously allocated buffer. This could ultimately allow for sensitive server memory to be corrupted, potentially resulting in the execution of arbitrary code.
Exploit / POC
Roger Wilco Remote Server Side Buffer Overrun Vulnerability
Luigi Auriemma <[email protected]> has supplied a proof of concept exploit 'wilco.zip' available at the following location:
http://www.zone-h.org/download/file=5019/
Exploit code has been provided by d4rkgr3y <[email protected]>.
Luigi Auriemma <[email protected]> has supplied a proof of concept exploit 'wilco.zip' available at the following location:
http://www.zone-h.org/download/file=5019/
Exploit code has been provided by d4rkgr3y <[email protected]>.
Solution / Fix
Roger Wilco Remote Server Side Buffer Overrun Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Roger Wilco Remote Server Side Buffer Overrun Vulnerability
References:
References:
- Roger Wilco Home Page (GameSpy)
- Rogerwilco: server's buffer overflow (Luigi Auriemma
)