Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet that specifies the length of data to read and then sends a second TCP packet that contains less data than specified, which causes Ratbag to repeatedly check the socket for more data.
Software | From | Fixed in |
---|---|---|
ratbag / dirt_track_racing_sprint_cars | - | - |
ratbag / leadfoot | - | - |
ratbag / dirt_track_racing | 1.0.3 | 1.0.3.x |
ratbag / dirt_track_racing | 2.0 | 2.0.x |
ratbag / world_of_outlaws_sprint_cars | - | - |
ratbag / dirt_track_racing_australia | - | - |