|
|
| |
|
| |
ut2003: Unreal Tournament 2003/2004 buffer overflow in 'secure' queries
| Package(s): | ut2003 |
CVE #(s): | |
| Created: | July 19, 2004 |
Updated: | July 21, 2004 |
| Description: |
The Unreal-based game servers support a specific type of query called
'secure'. Part of the Gamespy protocol, this query is used to ask if the
game server is able to calculate an exact response using a provided
string. Luigi Auriemma found that sending a long 'secure' query triggers a
buffer overflow in the game server. By sending a malicious UDP-based
'secure' query, an attacker could execute arbitrary code on the game
server. |
| Alerts: |
|
( Log in to post comments)
|
|
|