First published: Fri Apr 10 2009(Updated: )
The HTTP/XML-RPC service in Crysis 1.21 (game version 1.1.1.6156) and earlier allows remote attackers to cause a denial of service (crash) via a long HTTP request, which triggers a NULL pointer dereference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Crysis | =1.1 | |
Crysis | <=1.21 | |
Crysis | =1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6712 is classified as a denial of service vulnerability, which can lead to the crashing of the Crysis game.
To mitigate CVE-2008-6712, it is recommended to upgrade to Crysis version 1.21 or later.
CVE-2008-6712 is caused by a NULL pointer dereference triggered by a long HTTP request to the HTTP/XML-RPC service.
CVE-2008-6712 affects Crysis versions up to 1.21 and includes game version 1.1.1.6156 and earlier.
Yes, CVE-2008-6712 can be exploited remotely by attackers sending specially crafted HTTP requests to the vulnerable service.