ID Software Quake 3 "smurf...

- AV AC AU C I A
发布: 2001-07-17
修订: 2025-04-13

Quake 3 network play features contain a remotely exploitable denial of service vulnerability. A hostile client program can be used by to generate a large number of forged client queries on behalf of a target user. The server's responses flood the target user, consuming the target system's network bandwidth and CPU cycles. It has been reported that other games suffer from similar issues. Additional amplification attacks may be possible through the usage of commands which return detailed information about the game status or server information. In some cases, packets larger than 500 bytes may be sent in response to a 50 byte spoofed UDP packet.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息