Colin McRae Rally 2004 - Multiplayer Denial of Service



EKU-ID: 29585 CVE: OSVDB-10626 OSVDB-ID:
Author: Luigi Auriemma Published: 2004-06-04 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/10464/info

It is reported that Colin McRae Rally 2004 has a flaw handling server responses when entering the multiplayer menu of the game.

When entering the multiplayer menu, the game client sends a broadcast message requesting information from all servers on the local network. It is reported that an attacker is able to mimic a server and respond to these broadcast requests with an invalid response, causing a crash of the client game.

An attacker running a malicious server process could block all multiplayer access in a local network, denying service to all legitimate users.

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/24170.zip