Valve Software Half-Life 1.1 Client - Connection Routine Buffer Overflow (2)



EKU-ID: 28429 CVE: OSVDB-ID:
Author: anonymous Published: 2003-07-29 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/8299/info

Half-Life Client has been reported prone to a remotely exploitable buffer overflow condition.

The issue presents itself in the client connection routine, used by the client to negotiate a connection to the Half-Life game server. Due to a lack of sufficient bounds checking performed on both the parameter and value of data transmitted from the game server to the client, a malicious server may execute arbitrary code on an affected client.

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/22967.zip