Topic : | Server freezed in Skulltag 0.97d2-RC2
|
SecurityAlert : 3953
CVE : CVE-2008-2748
CWE : CWE-Other
SecurityRisk : Medium (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : Luigi Auriemma
Published : 22.06.2008
Affected Software : | Skulltag Team, Skulltag, 0.95c
Skulltag Team, Skulltag, 0.95d
Skulltag Team, Skulltag, 0.95e
Skulltag Team, Skulltag, 0.95f
Skulltag Team, Skulltag, 0.95g
Skulltag Team, Skulltag, 0.95h
Skulltag Team, Skulltag, 0.95i
Skulltag Team, Skulltag, 0.95j
Skulltag Team, Skulltag, 0.95k
Skulltag Team, Skulltag, 0.96b
Skulltag Team, Skulltag, 0.96c
Skulltag Team, Skulltag, 0.96d
Skulltag Team, Skulltag, 0.96e
Skulltag Team, Skulltag, 0.96f
Skulltag Team, Skulltag, 0.97d
Skulltag Team, Skulltag, 0.97d2, Release Candidate 2
Skulltag Team, Skulltag, 0.97d2, Release Candidate 3
Skulltag Team, Skulltag, 0.97d, Release Candidate 10
Skulltag Team, Skulltag, 0.97d, Release Candidate 9
Skulltag Team, Skulltag, 0.97d, Beta_4.1
Skulltag Team, Skulltag, 0.97d, Beta_4.2
Skulltag Team, Skulltag, 0.97d, Beta_4.3
Skulltag Team, Skulltag, 0.97d, Beta_4
Skulltag Team, Skulltag, 0.97d, Beta_3
Skulltag Team, Skulltag, 0.97d, Beta_2
Skulltag Team, Skulltag, 0.97d, Beta_1
Skulltag Team, Skulltag, 0.97b
Skulltag Team, Skulltag, 0.97c
Skulltag Team, Skulltag, 0.97c2
Skulltag Team, Skulltag, 0.97c3 |
 Advisory Content : #######################################################################
Luigi Auriemma
Application: Skulltag
http://www.skulltag.com
Versions: <= 0.97d2-RC2
Platforms: Windows, Linux and FreeBSD
Bug: loop during the parsing of the packets
Exploitation: remote, versus server
Date: 16 Jun 2008
Author: Luigi Auriemma
e-mail: aluigi (at) autistici (dot) org [email concealed]
web: aluigi.org
#######################################################################
1) Introduction
2) Bug
3) The Code
4) Fix
#######################################################################
===============
1) Introduction
===============
Skulltag is a port of the original Doom mainly focused on multiplayer
gaming.
#######################################################################
======
2) Bug
======
Skulltag is affected by a problem in the parsing of some packets with
the result of freezing the entine server for some seconds through the
sending of a single big malformed packet which is parsed multiple
times.
This Denial of Service can be made endless using multiple malformed
packets at regular intervals.
#######################################################################
===========
3) The Code
===========
http://aluigi.org/poc/skulltagloop.zip
#######################################################################
======
4) Fix
======
Version 0.97d2-RC3
#######################################################################
---
Luigi Auriemma
http://aluigi.org
References :
http://xforce.iss.net/xforce/xfdb/43125
http://www.securityfocus.com/bid/29760
http://www.securityfocus.com/archive/1/archive/1/493386/100/0/threaded
http://skulltag.com/testing/public/Skulltag%20Version%20History.txt
http://secunia.com/advisories/30668
http://aluigi.org/poc/skulltagloop.zip
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|