0verkill Game本地客户端多个缓冲区溢出漏洞

漏洞信息详情

0verkill Game本地客户端多个缓冲区溢出漏洞

漏洞简介

Overkill (0verkill) 0.15pre3存在多个缓冲区溢出漏洞。本地用户可以借助(1)load_cfg以及(2)save_cfg函数中的一个超长HOME环境变量在客户端执行任意代码;远程攻击者可能可以借助指向(3)send_message函数;以及在服务器中,借助(4)parse_command_line函数的超长字符串执行任意代码。

漏洞公告

Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com .
@securityfocus.com>

参考网址

来源: XF
名称: overkill-server-parsecommandline-bo(15000)
链接:http://xforce.iss.net/xforce/xfdb/15000

来源: XF
名称: overkill-client-multiple-bo(14999)
链接:http://xforce.iss.net/xforce/xfdb/14999

来源: BID
名称: 9550
链接:http://www.securityfocus.com/bid/9550

来源: www.securiteam.com
链接:http://www.securiteam.com/securitynews/5AP010KC0C.html

来源: BUGTRAQ
名称: 20040202 0verkill – little simple vulnerability.
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=107577335424509&w=2

来源: FULLDISC
名称: 20040202 0verkill – little simple vulnerability.
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016579.html

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享