Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange packet without a previous join packet, which causes Crysis to send a disconnect packet that includes unrelated log information.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://osvdb.org/46260 | vdb entry |
http://aluigi.altervista.org/adv/crysislog-adv.txt | |
http://secunia.com/advisories/30706 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/43087 | vdb entry |
http://www.securityfocus.com/bid/29720 | vdb entry exploit |