Originally posted by Error404
Very very interesting answers... really!
But you forgot just a thing or two...
1. First of all: you've to be connected. It could be. But it could be not. And if I'm not connected what's the vulnerability? *None at all*. Maybe you'll find this solution a bit crude but I find it very interesting...
Very very interesting answers... really!
![Smile](https://apolyton.net/core/images/smilies/smile.gif)
1. First of all: you've to be connected. It could be. But it could be not. And if I'm not connected what's the vulnerability? *None at all*. Maybe you'll find this solution a bit crude but I find it very interesting...
Reading works - read the original post and linked security advisories again.
2. We are talking about vulnerabilities of DOS attack. Not a dark person controlling my computer secretly and doing what he/she wants from the other corner of the world without possibility of my defence. Someone could make a non-right-handled-error-request to my civ4.exe application (that must be running - *must be*, it's not enough to have it installed) and make it crash. Do you realize how many *billions* other program could make it???? (I mean a DOS attack)
![Smile](https://apolyton.net/core/images/smilies/smile.gif)
If you had read the original post..and the linked security advisories...
Heres another one, just for "fun":
"Impact: DoS, System access
Where: From remote
Solution Status: Vendor Patch"
"The vulnerability is caused due to a boundary error in inftrees.c when handling corrupted compressed data streams. This can be exploited to crash any application that uses the zlib library, or potentially to execute arbitrary code with privileges of the vulnerable application.
The vulnerability has been reported in version 1.2.2. Prior versions may also be affected."
zlib version 1.2.2 ships with Civ 4.
3. Even if I'm connected and I'm running my cIV game in singleplayer, this hacker have to bypass my firewall - a very restrictive firewall
I do not autorize any program to access internet if I'm not the one using it. So a DOS attack directed to the civ4.exe application is completely harmless without my will.
![Smile](https://apolyton.net/core/images/smilies/smile.gif)
Yes, not playing multi would reduce the attack surface, but you would still be locally vulnerable - a corrupted play by email file, a corrupted save game file, corrupted mod file, etc etc.
In conclusion, the only possibility remaining is when I'm playing an on-line game.
And dont forget that the PYTHON24.DLL file also contains insecure zlib code - built right into it.
And what could be happen? My computer will crash. Ok, I lived 30 years with Windows that makes it possible every single moment of my life, I can stand it. ehehe
![Big Grin](https://apolyton.net/core/images/smilies/biggrin.gif)
1) Civ 4 crashes/closes.
2) Civ 4 crashes/closes and/or arbitrary code execution occurs, leading to remote system control
You folks really need to learn to read, and read comprehensively.
P.S.
However, as I said in my first post, those news you brought are usefull indeed and I've already updated everything. I was only complaining about the tone you used to say it... let's say just a little bit catastrophic for me...
However, as I said in my first post, those news you brought are usefull indeed and I've already updated everything. I was only complaining about the tone you used to say it... let's say just a little bit catastrophic for me...
![Wink](https://apolyton.net/core/images/smilies/wink.gif)
P.P.S.
I'm sorry for my - not so bright - english, it's not my native language...
I'm sorry for my - not so bright - english, it's not my native language...
Comment