Valve developers recently patched a serious security flaw that existed in all versions of the Steam client for the last ten years.
According to Tom Court, who discovered the security flaw, the vulnerability could allow a malicious user to execute code on any of the platform's 15 million users.

The exact terminology according to security researchers is RCE or remote code execution. The vulnerability could be exploited remotely via network requests without requiring access to the victim's computer. All the attacker had to do was send specially crafted UDP packets to their victim. The source of this vulnerability was a buffer overflow in one of the many libraries it uses, and more specifically in the code that "joins" previously fragmented packets.
The problem was almost fixed last July when Valve added ASLR (Address space layout randomization) protection to the client. After ASLR was implemented, the technique simply crashed the victim's client.
However, as mentioned above, the problem almost fixed with ASLR, as the original technique combined with Steam's more well-known memory location could succeed.
Steam has now patched the vulnerability that the bug reported on February 20th of this year, and its developers released an updated version of the beta client within 12 hours. Later on April 4th, it was applied to all versions of the Steam client.
After giving Steam users almost two months to patch the update, Steam published a video showing the vulnerability in real time.
[su_youtube url=”https://www.youtube.com/watch?v=0QaozC8S0Aw” width=”640″ height=”380″]https://www.youtube.com/watch?v=B7o0qA4L4So[/su_youtube]
