capnbry.net
http://capnbry.net/daoc/advisory20040323 CVE-2004-1855
Mythic Entertainment Dark Age of Camelot 1.6x - Encryption Key Signing
Record summary
CVE-2004-1855 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Dark Age of Camelot before 1.68 live patch does not sign the RSA public key, which could allow remote malicious servers to gain sensitive information via a man-in-the-middle attack.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMythic Entertainment Dark Age of Camelot 1.6x - Encryption Key SigningExploitDB exploitby Todd ChapmanNot analyzed1 file
References
620040323 Dark Age of Camelot login client vulnerability to man in the middle attackmailing list
http://lists.netsys.com/pipermail/full-disclosure/2004-March/019212.html 20040324 Dark Age of Camelot login client vulnerability to man in the middlemailing list
http://marc.info/?l=bugtraq&m=108016932816707&w=2 9960vdb entry
http://www.securityfocus.com/bid/9960 daoc-login-mitm(15597)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/15597 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-1855