Перейти к содержимому
View in the app

A better way to browse. Learn more.

Zloplay community

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.
Опубликовано:

I knew I saw that in other CoD games! And Google helped me remember: ._.

 

A] "Attempted to overrun string in call to va()" DoS

----------------------------------------------------

 

va() is a function of the Quake 3 engine used to quickly build strings

using snprintf and a static destination buffer.

If the generated string is longer than the available buffer the server

shows an "Attempted to overrun string in call to va()" error and

terminates.

From Call of Duty 2 (and consequently CoD4) the size of this buffer has

been reduced from the original 32000 bytes to only 1024 causing many

problems to the admins, for which reason I created an unofficial fix

for CoD2 in the far 2006 (http://aluigi.org/patches/cod2vawo.lpatch).

 

So in CoD4 an attacker which has joined the server can exploit this

vulnerability through the sending of a command longer than 1024 bytes

causing the immediate termination of the server.

 

Greetz

Mok'bara

Featured Replies

Гость
Эта тема закрыта для публикации сообщений.

Сейчас на странице 0

  • Нет пользователей, просматривающих эту страницу

Важная информация

Используя этот сайт, вы соглашаетесь Условия использования.

Account

Navigation

Поиск

Поиск

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.