PT-2007-6332 · Epic Games+1 · Unreal Engine+1
Publicado
2007-10-06
·
Atualizado
2018-10-15
·
CVE-2007-5249
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
Unreal engine versions prior to 2.8.2 (Special Forces)
Description:
The issue is related to multiple buffer overflows in the logging function of the Unreal engine when Punkbuster is enabled. This can be exploited by remote attackers to cause a denial of service, specifically a daemon crash, by sending a long packet to specific servers. The attack vectors include sending a long
PB Y packet to the YPG server on UDP port 1716 or a long PB U packet to UCON on UDP port 1716.Recommendations:
For Unreal engine versions prior to 2.8.2, consider disabling Punkbuster until a patch is available to prevent the exploitation of the buffer overflows in the logging function. Restrict access to the YPG server on UDP port 1716 and UCON on UDP port 1716 to minimize the risk of a denial of service attack.
Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Punkbuster
Unreal Engine