[<prev] [next>] [day] [month] [year] [list]
Message-ID: <007b01cc7e91$ad919a20$08b4ce60$@gmail.com>
Date: Thu, 29 Sep 2011 03:22:21 -0700
From: "Michael J. Gray" <mooseous@...il.com>
To: <full-disclosure@...ts.grok.org.uk>
Subject: GSC Voice Server Denial of Service Vulnerability
Product: GSC (Game Servers Client)
Version: 2.00 Build 3017
Website: http://getgsc.com
By inspecting the network traffic of messages to voice servers one can see
that ASCII strings are prefixed with their length as a 32-bit signed
integer. Simply modifying this to any length in excess of the actual
string's length will cause a denial of service to that voice server by
crashing it. This may be a precursor to a buffer overflow vulnerability, but
it appears not to be exploitable in this way at this time.
Content of type "text/html" skipped
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists