It is reported that Colin McRae Rally 2004 has a flaw handling server responses when entering the multiplayer menu of the game. When entering the multiplayer menu, the game client sends a broadcast message requesting information from all servers on the local network. It is reported that an attacker is able to mimic a server and respond to these broadcast requests with an invalid response, causing a crash of the client game. An attacker running a malicious server process could block all multiplayer access in a local network, denying service to all legitimate users.
It is reported that Colin McRae Rally 2004 has a flaw handling server responses when entering the multiplayer menu of the game. When entering the multiplayer menu, the game client sends a broadcast message requesting information from all servers on the local network. It is reported that an attacker is able to mimic a server and respond to these broadcast requests with an invalid response, causing a crash of the client game. An attacker running a malicious server process could block all multiplayer access in a local network, denying service to all legitimate users.