PT-2004-3265 · Red Storm · The Sum Of All Fears+2

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2371

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Red Storm web-based games, including Ghost Recon versions 1.4 and earlier Red Storm web-based games, including Desert Siege Red Storm web-based games, including The Sum of all Fears versions 1.1.1.0 and earlier
Description: The issue is related to improper checking of return values from certain functions, allowing remote attackers to cause a denial of service (hang) by sending packets that contain text strings with incorrect size values.
Recommendations: For Ghost Recon versions 1.4 and earlier, update to a version that properly checks return values from functions to prevent denial of service attacks. For Desert Siege, ensure proper input validation to prevent packets with incorrect size values from causing a denial of service. For The Sum of all Fears versions 1.1.1.0 and earlier, apply fixes that correctly handle return values from functions to mitigate the risk of denial of service attacks.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2371

Affected Products

Desert Siege
Ghost Recon
The Sum Of All Fears