Secunia Security Advisory - Luigi Auriemma has reported a vulnerability in PunkBuster, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a vulnerable system.
66c75bf6bdccad2e8e32c8ecf09bcdbf96964a3e9aa60d2c93144379aeef7f38
TITLE:
PunkBuster Cvars Monitoring Format String Vulnerability
SECUNIA ADVISORY ID:
SA18917
VERIFY ADVISORY:
http://secunia.com/advisories/18917/
CRITICAL:
Highly critical
IMPACT:
DoS, System access
WHERE:
>From remote
SOFTWARE:
PunkBuster 1.x
http://secunia.com/product/8131/
DESCRIPTION:
Luigi Auriemma has reported a vulnerability in PunkBuster, which can
be exploited by malicious people to cause a DoS (Denial of Service)
and potentially to compromise a vulnerable system.
The vulnerability is caused due to a format string error in the
PunkBuster server when kicking a client that has an invalid cvars
value. This can be exploited to crash the server and may allow
arbitrary code execution, by configuring the monitored cvars on a
client to include format string specifiers.
The vulnerability has been reported in version 1.180 and prior.
Note: The vulnerability is reportedly exploitable via Soldier of
Fortune II with PunkBuster enabled.
SOLUTION:
The vulnerability has reportedly been fixed by the vendor.
PROVIDED AND/OR DISCOVERED BY:
Luigi Auriemma
ORIGINAL ADVISORY:
http://aluigi.altervista.org/adv/sof2pbfs-adv.txt
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------