PT-2007-6332 · Epic Games+1 · Unreal Engine+1
Published
2007-10-06
·
Updated
2018-10-15
·
CVE-2007-5249
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
Unreal engine versions prior to 2.8.2 (Special Forces)
Description:
The issue is related to multiple buffer overflows in the logging function of the Unreal engine when Punkbuster is enabled. This can be exploited by remote attackers to cause a denial of service, specifically a daemon crash, by sending a long packet to specific servers. The attack vectors include sending a long
PB Y packet to the YPG server on UDP port 1716 or a long PB U packet to UCON on UDP port 1716.Recommendations:
For Unreal engine versions prior to 2.8.2, consider disabling Punkbuster until a patch is available to prevent the exploitation of the buffer overflows in the logging function. Restrict access to the YPG server on UDP port 1716 and UCON on UDP port 1716 to minimize the risk of a denial of service attack.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Punkbuster
Unreal Engine