Colin McRae Rally 2004 - Multiplayer Denial of Service
Author: Luigi Auriemma
type: dos
platform: multiple
port:
date_added: 2004-06-04
date_updated: 2013-01-22
verified: 1
codes: OSVDB-10626
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/10464/info
It is reported that Colin McRae Rally 2004 has a flaw handling server responses when entering the multiplayer menu of the game.
When entering the multiplayer menu, the game client sends a broadcast message requesting information from all servers on the local network. It is reported that an attacker is able to mimic a server and respond to these broadcast requests with an invalid response, causing a crash of the client game.
An attacker running a malicious server process could block all multiplayer access in a local network, denying service to all legitimate users.
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/24170.zip