PT-2007-5450 · Lfs Team · Live For Speed
N00B
·
Published
2007-08-08
·
Updated
2017-09-29
·
CVE-2007-4257
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Live for Speed versions S1 and S2
Description
The issue is related to multiple buffer overflows that can be exploited by user-assisted remote attackers to execute arbitrary code. This can be achieved through a
.spr file, which is a single player replay file containing a long user name, or a .ply file containing a long number plate string.Recommendations
For Live for Speed versions S1 and S2, consider disabling the processing of
.spr and .ply files until a patch is available to prevent the exploitation of buffer overflows. Restrict access to the functions that handle these file types to minimize the risk of arbitrary code execution.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Live For Speed