RSS   Vulnerabilities for 'Game networking sockets'   RSS

2020-12-03
 
CVE-2020-6017

CWE-787
 

 
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment() when configured to support plain-text messages, leading to a Heap-Based Buffer Overflow and resulting in a memory corruption and possibly even a remote code execution.

 
2020-12-02
 
CVE-2020-6018

CWE-787
 

 
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decrypt() when compiled using libsodium, leading to a Stack-Based Buffer Overflow and resulting in a memory corruption and possibly even a remote code execution.

 

 >>> Vendor: Valvesoftware 7 Products
Counter-strike
Steamos
Steam
Steam link firmware
Steam client
Dota 2
Game networking sockets


Copyright 2024, cxsecurity.com

 

Back to Top