PT-2002-1973 · Valve · Half-Life Server
Published
2002-10-04
·
Updated
2008-09-05
·
CVE-2002-0964
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
Half-Life Server versions 1.1.1.0 and earlier
Description:
The issue allows remote attackers to cause a denial of service, specifically resource exhaustion, by sending multiple responses to the initial challenge with different
cd key values. This action reaches the player limit, preventing other players from connecting until the original responses have timed out.Recommendations:
For Half-Life Server versions 1.1.1.0 and earlier, consider restricting the number of responses to the initial challenge to prevent reaching the player limit, or implement a mechanism to handle multiple responses with different
cd key values without causing resource exhaustion.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Half-Life Server