SA-MP Forums Archive
[Security] Buffer Overflow in server.cfg - Printable Version

+- SA-MP Forums Archive (https://sampforum.blast.hk)
+-- Forum: SA-MP (https://sampforum.blast.hk/forumdisplay.php?fid=3)
+--- Forum: Bug Reports (https://sampforum.blast.hk/forumdisplay.php?fid=20)
+--- Thread: [Security] Buffer Overflow in server.cfg (/showthread.php?tid=286098)



[Security] Buffer Overflow in server.cfg - Researcher - 26.09.2011

There exists a buffer overflow in samp-server.exe, which is a security issue if a server owner can be tricked into loading a malicious server.cfg file, causing execution of arbitrary code through a stack-based buffer overflow.


Re: [Security] Buffer Overflow in server.cfg - Scott - 27.09.2011

It'd probably be best to e-mail team@sa-mp.com the details in private.


Re: [Security] Buffer Overflow in server.cfg - Researcher - 28.09.2011

I already sent PM to a few high levels, no reply for while. I sent email to team address you gave, thanks.


Re: [Security] Buffer Overflow in server.cfg - playbox12 - 28.09.2011

Quote:
Originally Posted by Researcher
Посмотреть сообщение
I already sent PM to a few high levels, no reply for while. I sent email to team address you gave, thanks.
Make sure you specify some details regarding the issue (in the email or PM, ONLY to Kalcor). Don't post those details here though.


Re: [Security] Buffer Overflow in server.cfg - Researcher - 29.09.2011

I've gotten through, it will be fixed in the next version. Thanks everyone for your assistance. Cheers.