PT-2007-6332 · Epic Games+1 · Unreal Engine+1

Published

2007-10-06

·

Updated

2018-10-15

·

CVE-2007-5249

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Unreal engine versions prior to 2.8.2 (Special Forces)
Description: The issue is related to multiple buffer overflows in the logging function of the Unreal engine when Punkbuster is enabled. This can be exploited by remote attackers to cause a denial of service, specifically a daemon crash, by sending a long packet to specific servers. The attack vectors include sending a long PB Y packet to the YPG server on UDP port 1716 or a long PB U packet to UCON on UDP port 1716.
Recommendations: For Unreal engine versions prior to 2.8.2, consider disabling Punkbuster until a patch is available to prevent the exploitation of the buffer overflows in the logging function. Restrict access to the YPG server on UDP port 1716 and UCON on UDP port 1716 to minimize the risk of a denial of service attack.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5249

Affected Products

Punkbuster
Unreal Engine