PT-2009-2480 · Groove Games+3 · Warpath+8

Published

2009-08-19

·

Updated

2018-10-11

·

CVE-2008-7011

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Unreal Engine versions used in Unreal Tournament 3 1.3, Unreal Tournament 2003, Unreal Tournament 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops
Description The issue allows remote authenticated users to cause a denial of service, resulting in a server exit. This is achieved through multiple file downloads from the server, which triggers an assertion failure when the Closing flag in UnChan.cpp is set.
Recommendations For the affected versions of Unreal Engine used in Unreal Tournament 3 1.3, Unreal Tournament 2003, Unreal Tournament 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, consider restricting multiple file downloads from the server as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-7011

Affected Products

Dead Man'S Hand
Pariah
Postal 2
Shadow Ops
Unreal Engine
Unreal Tournament 2003
Unreal Tournament 2004
Unreal Tournament 3
Warpath