A Remote Code Execution Vulnerability in the Steam Client
contextis.com
contextis.com
Just the list of games I have and the DRM required to play them.
Doesn't all of that work through embedded web-browser?
They don’t seem to have a *nix referral, but seems totally possible to make.
Which is based on reverse engineering the Steam client, so you can implement game downloading yourself.
Just curious how it would've played out if a blackhat had discovered this instead.
It's not like a heap overflow wouldn't have been a big deal otherwise, for what it's worth.
The last thing they want to have to deal with is people reporting how running the game through steam costs a non-negligible amount of performance, or causes weird occasional lags/stalls while playing. In that respect, it's an extremely high performance application, in that it needs to be nigh unnoticeable to the type of people that overclock systems, push their graphics cards to their limits, and play games with FPS counters always showing in the corner.
In that respect, it may be a textbook case of an application where you want a very specific memory allocation scheme that falls within very strict performance guidelines.
[0] - https://github.com/ValveSoftware/source-sdk-2013/tree/master...
[1] - https://github.com/ValveSoftware/source-sdk-2013/tree/master...
Writing your own protocol and/or memory allocator without fuzzing either is also highly dubious.
For example, Googling "Jetty buffer reuse" immediately popped up their ByteBufferPool class: https://www.eclipse.org/jetty/javadoc/9.4.8.v20171121/org/ec...
I say despite because: a. With a system service you wouldn't need to change the ACLs b. now anyone everyone has a system service, yay!
* well, I haven't checked this week