First published: Wed Nov 18 2020(Updated: )
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_ReceiveUnreliableSegment(), leading to a Heap-Based Buffer Underflow and a free() of memory not from the heap, resulting in a memory corruption and probably even a remote code execution.
Credit: cve@checkpoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Valvesoftware Game Networking Sockets | <1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6016 is a vulnerability in Valve's Game Networking Sockets prior to version v1.2.0 that improperly handles unreliable segments with negative offsets, leading to a Heap-Based Buffer Underflow and a memory corruption.
The severity of CVE-2020-6016 is critical with a CVSS score of 9.8.
CVE-2020-6016 affects Valvesoftware Game Networking Sockets versions before v1.2.0.
CVE-2020-6016 can be exploited by sending unreliable segments with negative offsets, leading to a Heap-Based Buffer Underflow and memory corruption.
Yes, the fix for CVE-2020-6016 is available in version v1.2.0 of Valve's Game Networking Sockets.