vendor:
Lords of the Realm III
by:
Luigi Auriemma
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Lords of the Realm III
Affected Version From: 01.01
Affected Version To: 01.01
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2003
Lords of the Realm III <= 1.01 server crash
A problem in the handling of nicknames is reported in the Lords of the Realm III server. Because of this, an attacker may be able to deny service to users of the game server. The problem is in the handling of nicknames of excessive length. It should be noted that this vulnerability only occurs when the server enters 'lobby mode', which is a brief window of time before the initiation of a new game.
Mitigation:
Ensure that the server is not in 'lobby mode' when not necessary and limit the length of nicknames.