CNCVE编号:CNCVE-20000969 CVE编号:CVE-2000-0969 安全级别:高 漏洞中文描述: Half Life专用服务器build 3104早期版本中存在格式化字符串漏洞,导致远程攻击者通过从系统控制台或rcon把格式化字符串引入changelevel命令来执行任意程序。 漏洞英文描述: Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changelevel command, via the system console or rcon. 漏洞参考: BUGTRAQ:20001016 Half-Life Dedicated Server Vulnerability | URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0254.html | BUGTRAQ:20001024 Tamandua Sekure Labs Security Advisory 2000-01 | URL:http://www.securityfocus.com/archive/1/141 系统类型:其他 漏洞类型:输入有效性检查错误