SecurityAlert : 3983 CVE : CVE-2008-3135 CWE : CWE-399 SecurityRisk : Medium (About) Remote Exploit : Yes Local Exploit : No Victim interaction required : No Exploit Available : No Credit : Luigi Auriemma Published : 12.07.2008
Each UDP packet for this game can contain various blocks of data.
The type 0x80 forces the server to perform a cycle from zero to the 32
bit number (so max 0xffffffff) specified in that data block.
The maximum size of a packet supported by the game is 1400 bytes in
which is possible to place max 233 blocks of this type causing the
freeze of a server for over 2 hours (tested with a fast CPU).
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.