what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

strong2boom.txt

strong2boom.txt
Posted Aug 14, 2005
Authored by Luigi Auriemma | Site aluigi.altervista.org

Stronghold 2 versions 1.2 and below suffers from a denial of service flaw due to memory allocation issues with the STLport library.

tags | advisory, denial of service
SHA-256 | 976ad9a4db45122c9f94a89aa1c05cbc12d33cdf624c11b05ef389d9ba69831c

strong2boom.txt

Change Mirror Download

#######################################################################

Luigi Auriemma

Application: Stronghold 2
http://www.stronghold2.com
Versions: <= 1.2
Platforms: Windows
Bug: exception/crash
Exploitation: remote, versus server
Date: 30 May 2005
Author: Luigi Auriemma
e-mail: aluigi@autistici.org
web: http://aluigi.altervista.org


#######################################################################


1) Introduction
2) Bug
3) The Code
4) Fix


#######################################################################

===============
1) Introduction
===============


Stronghold 2 is a stategic game developed by Firefly Studios
(http://www.fireflyworlds.com) and published by 2K Games
(http://www.2kgames.com).
It has been released in April 2005.


#######################################################################

======
2) Bug
======


In the packet used for joining the server is locatd the client's
nickname preceded by a 32 bit number used to specify its size.
When the server receives the packet it reads this number and allocates
that amount of memory where, then, will be copied the nickname.
The problem is that the STLport library fails to allocate a too big
amount of memory and generates an exception that terminates the game.


#######################################################################

===========
3) The Code
===========


http://aluigi.altervista.org/poc/strong2boom.zip


#######################################################################

======
4) Fix
======


No fix.
No reply from the vendor.


#######################################################################


---
Luigi Auriemma
http://aluigi.altervista.org

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close