Actively Exploited in the Wild
This vulnerability is being actively exploited in the wild.
GTA SA-MP Server Buffer Overflow Vulnerability in server.cfg Processing
Vulnerability
A stack-based buffer overflow vulnerability has been identified in GTA San Andreas Multiplayer (SA-MP) server version 0.3.1.1. This vulnerability arises when the server processes a malformed server.cfg configuration file, particularly an echo directive with excessive input. Local attackers can exploit this flaw to execute arbitrary code by sending a crafted server.cfg file and having the victim run samp-server.exe.
Impact
Exploitation of this vulnerability allows for arbitrary code execution on the affected system.
Reproduction
To reproduce this vulnerability, overwrite the server.cfg file with a crafted version that includes excessive input in an echo directive. After replacing the original server.cfg with the crafted one, launch samp-server.exe. The buffer overflow will occur, leading to the execution of arbitrary code.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
