[NT] Raknet Denial of Service

From: SecuriTeam (support_at_securiteam.com)
Date: 06/09/05

  • Next message: SecuriTeam: "[TOOL] Tattle - Automatic Reporting Of SSH Brute-Force Attacks"
    To: list@securiteam.com
    Date: 9 Jun 2005 11:32:26 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      Raknet Denial of Service
    ------------------------------------------------------------------------

    SUMMARY

     <http://www.rakkarsoft.com> Raknet is a multi-license (GPL, shareware and
    commercial) network library for games developed by
    <http://www.rakkarsoft.com> Rakkarsoft. It has been used in many open and
    closed source games like those developed by <http://www.n-fusion.com>
    nFusion.
    Raknet based games vulnerable to denial of service when server receives
    maliciously crafted UDP packet.

    DETAILS

    Vulnerable Systems:
     * Raknet network library versions 2.33 and prior (before 30 May 2005).

    Immune Systems:
     * Raknet network library version 2.33 (05/30/2005) version not changed.

    An UDP packet of 0 bytes is able to freeze the game server. The problem is
    that when an empty packet is received the server should close the socket
    and return to the main menu (the first bug) but before doing that it
    enters in an endless loop that executes Sleep(10) until the main thread is
    active (but never terminates).

    Proof of concept:
     <http://aluigi.altervista.org/poc/rakzero.zip>
    http://aluigi.altervista.org/poc/rakzero.zip

    Patch Availability:
     <http://www.rakkarsoft.com/#Downloads> Version 2.33 (05/30/2005).
    The version number has not been changed so be sure to have the patched
    version released the 30 May 2005 or later.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:aluigi@autistici.org> Luigi
    Auriemma.
    The original article can be found at: <http://aluigi.altervista.org>
    http://aluigi.altervista.org

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[TOOL] Tattle - Automatic Reporting Of SSH Brute-Force Attacks"

    Relevant Pages

    • [NT] Simbin Racing Games Players Disconnection
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Simbin Racing Games Players Disconnection ... an UDP packet of zero bytes sent to ... int main{ ...
      (Securiteam)
    • [NT] Unreachable Socket in Lithtech Engine (New Protocol)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The Lithtech engine is a game engine used by many games. ... int timeout; ...
      (Securiteam)
    • [NT] Multiple Vulnerabilities in HP Web JetAdmin (Read, Write, Execute, Path Disclosure, Password De
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... HP Web JetAdmin is an enterprise management system for large amounts of HP ... The web server is a modular service ... HP Web JetAdmin uses it's own encryption. ...
      (Securiteam)
    • [NEWS] Multiple Vulnerabilities in Oracle Database (Character Conversion, Extproc, Password Disclosu
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Multiple vulnerabilities were discovered in the (Oracle database server ... password is required to exploit this vulnerability. ...
      (Securiteam)
    • [NEWS] ColdFusion MX Oversize Error Message DoS
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... ColdFusion MX "is the solution for building and deploying powerful web ... shoots up and stays there until the server completes writing the error ... a long string of data as a GET or POST request to ...
      (Securiteam)