Soldat game server 1.4.2 and earlier, and dedicated server 2.6.2 and earlier, allows remote attackers to cause a client denial of service (crash) via (1) a long string to the file transfer port or (2) a long chat message, or (3) a server denial of service (continuous beep and slowdown) via a string containing many 0x07 or other control characters to the file transfer port.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Soldat_dedicated_server | Michal_marcinkowski | * | 2.6.2 (including) |
Soldat_game_server | Michal_marcinkowski | * | 1.4.2 (including) |