PT-2007-6332 · Epic Games+1 · Unreal Engine+1

Publicado

2007-10-06

·

Atualizado

2018-10-15

·

CVE-2007-5249

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Unreal engine versions prior to 2.8.2 (Special Forces)
Description: The issue is related to multiple buffer overflows in the logging function of the Unreal engine when Punkbuster is enabled. This can be exploited by remote attackers to cause a denial of service, specifically a daemon crash, by sending a long packet to specific servers. The attack vectors include sending a long PB Y packet to the YPG server on UDP port 1716 or a long PB U packet to UCON on UDP port 1716.
Recommendations: For Unreal engine versions prior to 2.8.2, consider disabling Punkbuster until a patch is available to prevent the exploitation of the buffer overflows in the logging function. Restrict access to the YPG server on UDP port 1716 and UCON on UDP port 1716 to minimize the risk of a denial of service attack.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5249

Produtos afetados

Punkbuster
Unreal Engine