Infocom公司1983年发行的交互式冒险游戏《Infidel》中存在一个严重的内存溢出漏洞1。该漏洞源于ZIL编译器在处理全局变量默认值时的错误,导致DESERT-TO-TABLE例程向错误的内存地址写入数据1。这一缺陷在原始版本和1984年版本中均存在,在游戏发行数十年间从未被发现1。
具体而言,ZIL编译器将TBL参数初始化为常量值30,而非DESERT-TABLE的正确地址111291。当玩家在游戏的无尽沙漠中放置9个物品时,这一错误就会被触发,数据写入地址30-63(本应未使用的区域),最终覆盖地址64及以后的缩写表数据1。这导致游戏文本输出出现混乱,如"You"被替代为"the"等异常现象,最终可能导致游戏崩溃1。根本原因在于Infocom的测试团队未在无尽沙漠场景中进行充分的对象放置测试1。
A severe memory overflow bug has been uncovered in Infocom's 1983 interactive adventure game Infidel, decades after its initial release. 1 The vulnerability stems from an error in the ZIL compiler's handling of global variable default values, specifically in the DESERT-TO-TABLE routine, which writes data to an incorrect memory address and corrupts the abbreviation table, causing game text to display incorrectly or triggering crashes. 1 The flaw persisted undetected across multiple releases, including the original version (serial 830916) and the Macintosh release (serial 840522). 1
The root cause traces to the ZIL compiler initializing the TBL parameter to a constant value of 30 rather than pointing to the actual address of DESERT-TABLE at 11129. 1 This misalignment causes data writes to addresses 30-63, which should remain unused, ultimately overwriting the abbreviation table beginning at address 64 and beyond. 1 The bug manifests when players place nine objects in the endless desert, after which the game begins substituting words—for example, displaying "You" where "the" should appear. 1 Investigation revealed that Infocom's testing team failed to conduct adequate object placement testing within the desert environment, allowing the defect to escape quality assurance. 1
评论
还没有评论,欢迎留下第一条。