Monolith Lithtech游戏引擎远程服务拒绝漏洞

漏洞信息详情

Monolith Lithtech游戏引擎远程服务拒绝漏洞

漏洞简介

用于(1)Contract Jack 1.1及其早期版本,(2)No one lives forever 2 1.3及其早期版本,(3)Tron 2.0 1.042及其早期版本,(4)F.E.A.R. (First Encounter Assault and Recon)和可能其它游戏中的Lithtech engine存在漏洞。远程攻击者可以借助UDP数据包导致服务拒绝(连接拒绝),并导致recvfrom产生返回代码而导致监听循环结束。

漏洞公告

The vendor has released a patch addressing this issue for F.E.A.R. Users are advised to contact the vendor for details on obtaining the appropriate update.

参考网址

来源: FULLDISC
名称: 20041213 Socket unreacheable in the Lithtech engine (new protocol)
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/029932.html

来源: aluigi.altervista.org
链接:http://aluigi.altervista.org/adv/lithsock-adv.txt

来源: XF
名称: lithtech-engine-communication-dos(18456)
链接:http://xforce.iss.net/xforce/xfdb/18456

来源: BID
名称: 11902
链接:http://www.securityfocus.com/bid/11902

来源: SECUNIA
名称: 17317
链接:http://secunia.com/advisories/17317

来源: SECUNIA
名称: 13446
链接:http://secunia.com/advisories/13446/

来源: BUGTRAQ
名称: 20041213 Socket unreacheable in the Lithtech engine (new protocol)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=110297515500671&w=2

来源: FULLDISC
名称: 20051021 F.E.A.R. 1.01 likes lithsock
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2005-October/038095.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享