[bf1942] New update?

Markus Thurlin thurlin at algonet.se
Wed Dec 1 18:50:27 EST 2004


The exploit probably is in the network protocol between the server and the
client, because changes to that would probably be the only thing that
requires both server and client to be patched.
Reading the homepage of Luigi Auriemma http://aluigi.altervista.org/ makes
me believe that the Fake Players Bug is what EA has fixed.
Fixing that would require changes to both client and server.
Although, it doesnt seem like the Fake Player Bug is something that would
require immidiate attention, since its pretty harmless in a way.

----- Original Message ----- 
From: "Rick Thompson" <rick at fortweb.com>
To: <bf1942 at icculus.org>
Sent: Thursday, December 02, 2004 12:09 AM
Subject: [SPAM][97.7%] RE: [bf1942] New update?


> I have to agree with that logic, much better to announce it without
warning
> after a patch is available.
>
> The only problem is I still haven't seen an announcement on this list and
> it just keeps getting worse. First off it's a security issue then there is
> no nix server patch then the patched client won't run under rc2... when
> exactly are we going to be given a clue?
>
> "Please don't update your possibly exploitable clients if you want to play
> on your server and no, I have no idea when you will be able to." Man, the
> wording for this client mailing is going to take some work :)
>
> Rick
>
>
> At 10:01 PM 12/1/2004 +0100, you wrote:
> >If EA would release a test version of the patch and say that the patch
> >covers an important security issue, then half the world would look for
that
> >issue, and perhaps find the problem, and abuse it, because the patch
hasn't
> >been released to the public. Releasing the news and the patch at the same
> >time is the only correct thing to do in cases like these
> >
> >Jorrit
>


----------------------------------------------------------------------------
----


>
> ---
> Outgoing mail is certified Virus Free.
> Checked by AVG anti-virus system (http://www.grisoft.com).
> Version: 6.0.802 / Virus Database: 545 - Release Date: 11/26/2004
>




More information about the Bf1942 mailing list