|
|
| |
Glider collect'n kill is "a high speed flight shooter developed by REVOgames and released at October 2005".
A buffer overflow vulnerability exists in Glider Collect'n Kill game when client sends player name to the server. |
| |
Credit:
The information has been provided by Luigi Auriemma.
The original article can be found at: http://aluigi.altervista.org/adv/gliderbof-adv.txt
|
| |
Vulnerable Systems:
* Glider Collect'n Kill version 1.0.0.0
A buffer-overflow happens during the copying of the player name sent by the clients with the gl_playerEnter command in a buffer of about 4 kilobytes.
Proof of concept:
http://aluigi.altervista.org/poc/gliderbof.zip
Vendor Status:
No fix.
No reply from the vendor.
|
|
|