Serious Sam Engine Remote Denial of Service Vulnerability
BID:8936
Info
Serious Sam Engine Remote Denial of Service Vulnerability
| Bugtraq ID: | 8936 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 30 2003 12:00AM |
| Updated: | Oct 30 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Luigi Auriemma <[email protected]>. |
| Vulnerable: |
SeriousSam The Second Encounter demo SeriousSam The Second Encounter 1.0.5 SeriousSam The First Encounter 1.0.5 SeriousSam SeriousSam Test 2 2.1 a |
| Not Vulnerable: |
SeriousSam The Second Encounter 1.0.7 |
Discussion
Serious Sam Engine Remote Denial of Service Vulnerability
It has been reported that Serious Sam game engine is vulnerable to a remote denial of service vulnerability due to a failure to handle exceptional conditions. This issue occurs when the client sends a certain malformed parameter to the server. This request may cause the software to consume an excessive amount of CPU cycles leading to a crash or hang.
Successful exploitation of this issue may allow an attacker to cause the software to act in an unstable manner leading to a crash or hang.
It has been reported that Serious Sam engines and games that run on the TCP protocol are vulnerable to this issue however other games and versions could be affected as well.
It has been reported that Serious Sam game engine is vulnerable to a remote denial of service vulnerability due to a failure to handle exceptional conditions. This issue occurs when the client sends a certain malformed parameter to the server. This request may cause the software to consume an excessive amount of CPU cycles leading to a crash or hang.
Successful exploitation of this issue may allow an attacker to cause the software to act in an unstable manner leading to a crash or hang.
It has been reported that Serious Sam engines and games that run on the TCP protocol are vulnerable to this issue however other games and versions could be affected as well.
Exploit / POC
Serious Sam Engine Remote Denial of Service Vulnerability
Exploit code has been provided:
Exploit code has been provided:
Solution / Fix
Serious Sam Engine Remote Denial of Service Vulnerability
Solution:
The vendor has released a patch for Serious Sam: the second encounter. The fix 1.07 may be downloaded from the vendor.
Solution:
The vendor has released a patch for Serious Sam: the second encounter. The fix 1.07 may be downloaded from the vendor.
References
Serious Sam Engine Remote Denial of Service Vulnerability
References:
References:
- Homepage (SeriousEngine)
- Serious Sam is not so serious (Luigi Auriemma
)