PT-2007-5702 · Michał Marcinkowski · Soldat Dedicated Server+1
Luigi Auriemma
·
Publicado
2007-08-25
·
Atualizado
2018-10-15
·
CVE-2007-4531
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Soldat game server versions 1.4.2 and earlier
Soldat dedicated server versions 2.6.2 and earlier
Description
The issue allows remote attackers to cause a denial of service. This can be achieved through a long string to the file transfer port, a long chat message, or a string containing many control characters, such as 0x07, to the file transfer port, resulting in a client crash or a server denial of service characterized by a continuous beep and slowdown.
Recommendations
For Soldat game server versions 1.4.2 and earlier, consider restricting the length of strings accepted by the file transfer port and chat messages to prevent denial of service attacks.
For Soldat dedicated server versions 2.6.2 and earlier, restrict access to the file transfer port to minimize the risk of exploitation, and limit the acceptance of strings containing control characters.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Soldat Dedicated Server
Soldat Game Server