MOHAA linux server with potential exploit fix.

Ryan C. Gordon icculus at clutteredmind.org
Thu Jul 22 00:28:24 EDT 2004


Ok, I looked into the MOHAA buffer overflow, and I _think_ that I have a 
  fix. I say "think" because I'm screwing with this from a hotel room 
over ssh and don't have a MOHAA client installed to test locally, or 
even MOHAA installed remotely to make sure the server will even start up.

In short, please consider this to be an extremely unstable beta until 
proven otherwise.

    http://icculus.org/betas/mohaa/mohaa-lnxded-07222004.tar.bz2

Download, unpack, replace mohaa_lnxded and fgameded.so in your server 
installation.

Please note that this build was built with gcc3, and will need an 
external support library. Explanation of what to do if you get an error 
about "libstdc++" or something instead of a running server is here:

    https://bugzilla.icculus.org/show_bug.cgi?id=1801

If someone can confirm that this build does indeed close the exploit and 
doesn't generally suck, I'll do the same for Spearhead, too.

Thanks,
--ryan.





More information about the Mohaa mailing list