Valve Steam Client Detection Denial of Service Vulnerability
Vulnerability Details
This vulnerability allows remote attackers to execute a denial of service attack on vulnerable installations of Valve Steam. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the Steam client detection protocol. By responding to a broadcast packet with a crafted response, an attacker can cause the Steam process to crash.
Additional Details
Valve has issued an update to correct this vulnerability. More details can be found at:
http://store.steampowered.com/news/16801/
Disclosure Timeline
- 2015-05-14 - Vulnerability reported to vendor
- 2015-05-19 - Coordinated public release of advisory
Credit
Elvis Collado - HP DVLabs