An update was released tonight for Counter-Strike: Source that fixes a handful of engine exploits. The update is optional for server admins, but is recommended.
Server admins should run hldsupdatetool to grab these fixes. Clients should already know the drill by now, if not, restarting Steam may job your memory.
Engine
• Fixed an exploit that allowed files to be uploaded to the server at arbitrary locations in the file system
• Fixed a server crash caused by a client packet claiming to be an HLTV client when HLTV is disabled on the server
• Fixed a server crash caused by spoofing a client disconnect message
• Fixed a server crash caused by sending malformed reliable subchannel data
Counter-Strike: Source
• Novint Falcon support is now enabled by default
• Fixed an exploit that allowed files to be uploaded to the server at arbitrary locations in the file system
• Fixed a server crash caused by a client packet claiming to be an HLTV client when HLTV is disabled on the server
• Fixed a server crash caused by spoofing a client disconnect message
• Fixed a server crash caused by sending malformed reliable subchannel data
Counter-Strike: Source
• Novint Falcon support is now enabled by default
Server admins should run hldsupdatetool to grab these fixes. Clients should already know the drill by now, if not, restarting Steam may job your memory.