PT-2002-1973 · Valve · Half-Life Server

Published

2002-10-04

·

Updated

2008-09-05

·

CVE-2002-0964

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Half-Life Server versions 1.1.1.0 and earlier
Description: The issue allows remote attackers to cause a denial of service, specifically resource exhaustion, by sending multiple responses to the initial challenge with different cd key values. This action reaches the player limit, preventing other players from connecting until the original responses have timed out.
Recommendations: For Half-Life Server versions 1.1.1.0 and earlier, consider restricting the number of responses to the initial challenge to prevent reaching the player limit, or implement a mechanism to handle multiple responses with different cd key values without causing resource exhaustion.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0964

Affected Products

Half-Life Server