Crash in Alpha Black Zero 1.04

From: Luigi Auriemma (aluigi_at_autistici.org)
Date: 09/29/04

  • Next message: debian-security-announce_at_lists.debian.org: "[Full-Disclosure] [SECURITY] [DSA 555-1] New frenet6 packages fix potential information leak"
    Date: Wed, 29 Sep 2004 21:11:57 +0000
    To: bugtraq@securityfocus.com, bugs@securitytracker.com, news@securiteam.com, full-disclosure@lists.netsys.com, vuln@secunia.com
    
    

    #######################################################################

                                 Luigi Auriemma

    Application: Alpha Black Zero: Intrepid Protocol
                  http://www.playlogicgames.nl/abz/
    Versions: <= 1.04
    Platforms: Windows
    Bug: crash
    Risk: medium
    Exploitation: remote, versus server
    Date: 29 September 2004
    Author: Luigi Auriemma
                  e-mail: aluigi@altervista.org
                  web: http://aluigi.altervista.org

    #######################################################################

    1) Introduction
    2) Bug
    3) The Code
    4) Fix

    #######################################################################

    ===============
    1) Introduction
    ===============

    Alpha Black Zero (ABZ) is a third person strategic shooter developed by
    Khaeon (http://www.khaeon.nl) and released in August 2004.

    #######################################################################

    ======
    2) Bug
    ======

    Like any existent game, also ABZ supports a maximum nuber of players in
    multiplayer mode.
    The problem is that players are not limited by the server which crashs
    if too much clients tries to join.
    Then the possibility to emulate a join request with only one UDP packet
    makes the bug very easy to exploit.

    #######################################################################

    ===========
    3) The Code
    ===========

    http://aluigi.altervista.org/poc/abzboom.zip

    #######################################################################

    ======
    4) Fix
    ======

    No fix.
    The game is no longer supported.

    #######################################################################

    ---
    Luigi Auriemma
    http://aluigi.altervista.org


  • Next message: debian-security-announce_at_lists.debian.org: "[Full-Disclosure] [SECURITY] [DSA 555-1] New frenet6 packages fix potential information leak"

    Relevant Pages