PT-2004-2704 · Epic Games · Unreal Engine

Publicado

2004-12-31

·

Atualizado

2017-07-11

·

CVE-2004-1805

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Unreal Engine version 436
Description The issue is related to a format string vulnerability in games that utilize the Epic Games Unreal Engine. This vulnerability can be exploited by remote attackers to cause a denial of service, resulting in a crash, and potentially execute arbitrary code. The exploitation is achieved through the use of format string specifiers in class names.
Recommendations For Unreal Engine version 436, consider applying patches or updates that address format string vulnerabilities, specifically focusing on the proper handling of class names to prevent arbitrary code execution and denial of service attacks. As a temporary workaround, restrict the use of format string specifiers in class names until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1805

Produtos afetados

Unreal Engine