5th street - 'dx8render.dll' Format String



EKU-ID: 36904 CVE: CVE-2008-3116;OSVDB-47847 OSVDB-ID:
Author: superkhung Published: 2008-06-25 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/29928/info

The '5th street' game is prone to a format-string vulnerability.

Exploiting this issue will allow attackers to execute arbitrary code with the privileges of a user running the application. Failed attacks will likely cause denial-of-service conditions.

When the following chat message is sent, the game client of every connected user will crash:

%5000000.x