CVE-2021-30481
Severity CVSS v4.0:
Pending analysis
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
10/04/2021
Last modified:
03/11/2025
Description
Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffer overflow that occurs for a Steam invite after one click.
Impact
Base Score 3.x
8.00
Severity 3.x
HIGH
Base Score 2.0
6.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:valvesoftware:steam_client:*:*:*:*:*:*:*:* | 2021-04-10 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://news.ycombinator.com/item?id=26762170
- https://twitter.com/floesen_/status/1337107178096881666
- https://twitter.com/the_secret_club/status/1380868759129296900
- https://www.youtube.com/watch?v=rNQn--9xR1Q
- https://news.ycombinator.com/item?id=26762170
- https://twitter.com/floesen_/status/1337107178096881666
- https://twitter.com/the_secret_club/status/1380868759129296900
- https://www.youtube.com/watch?v=rNQn--9xR1Q



