LWN.net Logo

ut2003: Unreal Tournament 2003/2004 buffer overflow in 'secure' queries

Package(s):ut2003 CVE #(s):
Created:July 19, 2004 Updated:July 21, 2004
Description: The Unreal-based game servers support a specific type of query called 'secure'. Part of the Gamespy protocol, this query is used to ask if the game server is able to calculate an exact response using a provided string. Luigi Auriemma found that sending a long 'secure' query triggers a buffer overflow in the game server. By sending a malicious UDP-based 'secure' query, an attacker could execute arbitrary code on the game server.
Alerts:
Gentoo 200407-14 2004-07-19

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds