PT-2009-2480 · Groove Games+3 · Warpath+8
Published
2009-08-19
·
Updated
2018-10-11
·
CVE-2008-7011
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Unreal Engine versions used in Unreal Tournament 3 1.3, Unreal Tournament 2003, Unreal Tournament 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops
Description
The issue allows remote authenticated users to cause a denial of service, resulting in a server exit. This is achieved through multiple file downloads from the server, which triggers an assertion failure when the Closing flag in UnChan.cpp is set.
Recommendations
For the affected versions of Unreal Engine used in Unreal Tournament 3 1.3, Unreal Tournament 2003, Unreal Tournament 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, consider restricting multiple file downloads from the server as a temporary workaround to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dead Man'S Hand
Pariah
Postal 2
Shadow Ops
Unreal Engine
Unreal Tournament 2003
Unreal Tournament 2004
Unreal Tournament 3
Warpath