5th street - 'dx8render.dll' Format String

EDB-ID:

31964


Author:

superkhung

Type:

dos


Platform:

Windows

Date:

2008-06-25


source: https://www.securityfocus.com/bid/29928/info

The '5th street' game is prone to a format-string vulnerability.

Exploiting this issue will allow attackers to execute arbitrary code with the privileges of a user running the application. Failed attacks will likely cause denial-of-service conditions.

When the following chat message is sent, the game client of every connected user will crash:

%5000000.x