Halo Client Server Denial of Service Vulnerability
- 0
- Add a Comment
- No Related Post
Critical: Less critical Impact: DoS Where: From remote Solution Status: Vendor Patch Software: Halo 1.x
Luigi Auriemma has reported a vulnerability in Halo, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to a NULL pointer dereference error in the handling of server replies when browsing the list of online servers. This can be exploited by a malicious game server to crash client by returning a specially crafted reply.
The vulnerability has been reported in version 1.05. Prior versions may also be affected.
Solution: Update to version 1.06.
http://www.microsoft.com/games/pc/halo.aspx#downloads
