Vulnerabilities found in Armed Assault & Armed Assault II

Find a good article? Got a news story to share? VR, AR, 3D...it's all good! No self promotion please.
Post Reply
User avatar
gisabun
3D Angel Eyes (Moderator)
Posts: 215
Joined: Wed Mar 28, 2007 1:54 pm

Vulnerabilities found in Armed Assault & Armed Assault II

Post by gisabun »

Taken from the SANS Institute newsletter....

LOW: Armed Assault Multiple Vulnerabilities
Affected:
Armed Assault version 1.14 and prior
Armed Assault II version 1.02 and prior

Description: Armed Assault is a tactical military shooter war game
developed by Bohemia Interactive. Multiple vulnerabilities have been
identified in Armed Assault which might lead to a denial-of-service
condition or even arbitrary code execution. The first issue is caused
due to an error in the handling of the last field of the join packet.
The second issue is a format string error while processing the nickname
or the datafile field of a specially crafted join packet. The third
issue is an error caused due to inadequate checks on the voice data
packets sent to port 2305. Technical details for these vulnerabilities
are publicly available along with proof-of-concepts.

Status: Vendor confirmed, updates available.

References:
Wikipedia Article on Armed Assault
http://en.wikipedia.org/wiki/ArmA:_Armed_Assault" onclick="window.open(this.href);return false;
Vendor Home Page
http://www.bistudio.com/" onclick="window.open(this.href);return false;
Secunia Advisory
http://secunia.com/advisories/35900/" onclick="window.open(this.href);return false;
Image
Post Reply

Return to “User Contributed Immersive Technology News & Announcements”