Multiple Remote Denial of Service Vulnerabilities in Game SWAT 4

by arthack on 2008-07-26 16:38:20

Affected System:

Sierra Entertainment, Inc SWAT 4 <= 1.1

Description: BUGTRAQ ID: 30299

SWAT 4 is a squad-based tactical shooter game developed by Sierra Entertainment.

SWAT 4 has a vulnerability when processing malformed user requests. If a remote attacker sends a null pointer to the FString function via the VERIFYCONTENT or GAMECONFIG command before joining the game server, it will cause the server to crash. Additionally, if an RS string larger than 71 bytes is appended after the GAMESPYRESPONSE command, it will trigger a Runtime Error.