Server Buffer Overflow Vulnerability
Lornath
Join Date: 2002-11-30 Member: 10280Members
<div class="IPBDescription">crash and potential code execution</div> This was just released today:
<a href='http://www.pivx.com/press_releases/valve_release01.html' target='_blank'>hl server vulnerability</a>. I tried out the two exploits and sure enuff, they crashed or froze the server. The provided <a href='http://www.pivx.com/preparationv/' target='_blank'>fix</a> prevented the exploits.
-Lorn
<a href='http://www.pivx.com/press_releases/valve_release01.html' target='_blank'>hl server vulnerability</a>. I tried out the two exploits and sure enuff, they crashed or froze the server. The provided <a href='http://www.pivx.com/preparationv/' target='_blank'>fix</a> prevented the exploits.
-Lorn
Comments
It "worked" quite well...
- Kar
lol wasn't me. Just saw <a href='http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0061.html' target='_blank'>the vulnerability</a> today on the <a href='http://www.vulnwatch.org/' target='_blank'>vulnwatch mailing list</a>. Tried it out on my own server and it seemed like a legit issue. Thought I'd post here so other people could patch up their servers.
-Lorn
Nice of them to release a fix for windows servers but not for linux.
I'm not for security by obscurity, but I can't see the point in releasing exploit code when there is nothing you can do about it. Problem created by Valve, mass DOS caused by PivX Solutions.
Already had 2 of our servers killed by this in the last few hours.
<!--emo&???--><img src='http://www.unknownworlds.com/forums/html/emoticons/confused.gif' border='0' style='vertical-align:middle' alt='confused.gif'><!--endemo-->