[] NeoSense

Colin McRae Rally 2004 - Multiplayer Denial of Service

Author: Luigi Auriemma
type: dos
platform: multiple
port: 
date_added: 2004-06-04 
date_updated: 2013-01-22 
verified: 1 
codes: OSVDB-10626 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/10464/info

It is reported that Colin McRae Rally 2004 has a flaw handling server responses when entering the multiplayer menu of the game.

When entering the multiplayer menu, the game client sends a broadcast message requesting information from all servers on the local network. It is reported that an attacker is able to mimic a server and respond to these broadcast requests with an invalid response, causing a crash of the client game.

An attacker running a malicious server process could block all multiplayer access in a local network, denying service to all legitimate users.

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/24170.zip