Vulnerability Description
The client detection protocol in Valve Steam allows remote attackers to cause a denial of service (process crash) via a crafted response to a broadcast packet.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Valvesoftware | Steam Client | < 2015-05-13 |
Related Weaknesses (CWE)
References
- http://store.steampowered.com/news/16801/PatchVendor Advisory
- http://www.securityfocus.com/bid/74735Third Party AdvisoryVDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-15-233/Third Party AdvisoryVDB Entry
- http://store.steampowered.com/news/16801/PatchVendor Advisory
- http://www.securityfocus.com/bid/74735Third Party AdvisoryVDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-15-233/Third Party AdvisoryVDB Entry
FAQ
What is CVE-2015-4016?
CVE-2015-4016 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The client detection protocol in Valve Steam allows remote attackers to cause a denial of service (process crash) via a crafted response to a broadcast packet.
How severe is CVE-2015-4016?
CVE-2015-4016 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-4016?
Check the references section above for vendor advisories and patch information. Affected products include: Valvesoftware Steam Client.