漏洞信息详情
Monolith Lithtech游戏引擎远程服务拒绝漏洞
- CNNVD编号:CNNVD-200412-887
- 危害等级: 中危
- CVE编号:
CVE-2004-1395
- 漏洞类型:
其他
- 发布时间:
2004-12-31
- 威胁类型:
远程
- 更新时间:
2006-06-15
- 厂 商:
monolith_productions - 漏洞来源:
Discovery of this … -
漏洞简介
用于(1)Contract Jack 1.1及其早期版本,(2)No one lives forever 2 1.3及其早期版本,(3)Tron 2.0 1.042及其早期版本,(4)F.E.A.R. (First Encounter Assault and Recon)和可能其它游戏中的Lithtech engine存在漏洞。远程攻击者可以借助UDP数据包导致服务拒绝(连接拒绝),并导致recvfrom产生返回代码而导致监听循环结束。
漏洞公告
The vendor has released a patch addressing this issue for F.E.A.R. Users are advised to contact the vendor for details on obtaining the appropriate update.
参考网址
来源: FULLDISC
名称: 20041213 Socket unreacheable in the Lithtech engine (new protocol)
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/029932.html
来源: aluigi.altervista.org
链接:http://aluigi.altervista.org/adv/lithsock-adv.txt
来源: XF
名称: lithtech-engine-communication-dos(18456)
链接:http://xforce.iss.net/xforce/xfdb/18456
来源: BID
名称: 11902
链接:http://www.securityfocus.com/bid/11902
来源: SECUNIA
名称: 17317
链接:http://secunia.com/advisories/17317
来源: SECUNIA
名称: 13446
链接:http://secunia.com/advisories/13446/
来源: BUGTRAQ
名称: 20041213 Socket unreacheable in the Lithtech engine (new protocol)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=110297515500671&w=2
来源: FULLDISC
名称: 20051021 F.E.A.R. 1.01 likes lithsock
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2005-October/038095.html