HLDS woes

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • CSN NewsBot

    #1

    HLDS woes

    PJ_Hooker spotted over at Linux Games that there are 4 bugs that currently haunt HLDS, even the latest versions of build 1572 for Windows and 1573 for Linux. I'm pretty sure they will fixed in the upcoming patch, but here they are just for your interest.
    1) When the 'map' command is sent more than 58 or 59 characters a potentially exploitable buffer overflow occurs.



    2) When 235 or more characters are used with the 'exec' command a buffer is overflowed and the server crashes.



    3) There is a string formatting vulnerabilitiy in the 'map' command. When it recieves any formatting characters like %s or %d it interprets them as format characters and if crafted right a user could crash the server or execute code as the user the server is running as.



    4) There is a buffer overflow in the parsing of config files which could be used to execute code as the user running the server. This is dangerous because someone could place code in the config file of a module and distribute it to unsuspecting users.
    The server's already slow like a turtle on anti-speed, and only Linux 1.1 is out.. yeah go-- nevermind rizzuh told me not to make fun of *******.
Working...