Bugtraq mailing list archives

Re: Half Life dedicated server Patch


From: Nathan Woodcock <nathan () NL DEMON NET>
Date: Fri, 27 Oct 2000 12:48:43 -0000

New features and fixes include:
- Linux security issue resolved. <---------------------

  The patch was released earlier today. The 
linuxreadme.txt file
included in the release noted this as the only 
security related change:

- Rcon buffer overflow fixed.

It does not make any mention of the format string 
bug as mentioned in
'Tamandua Sekure Labs Security Advisory 2000-01'

Leon Hartwig, the coder of the linux half-life patch 
port, has confirmed in email on the hlds_linux mailing 
list that this exploit was most definately fixed.


Current thread: