|
Unreal Engine "secure" Query Buffer Overflow Vulnerability
|
|
Secunia Advisory:
|
SA11900
|
|
|
Release Date:
|
2004-06-22
|
|
Last Update:
|
2004-07-06
|
|
Popularity:
|
32,229 views
|
|
|
Critical:
|
 Highly critical
|
|
Impact:
|
System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Unreal Engine
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: Luigi Auriemma has reported a vulnerability in the Unreal Engine, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to a boundary error within the processing of secure queries, which are used to verify that a queried server is a legit Unreal server. This can be exploited to cause a buffer overflow by sending an overly long challenge string to a vulnerable server.
Successful exploitation may allow execution of arbitrary code.
The following games are reportedly affected:
* DeusEx (build 1.112fm and prior)
* Devastation (build 390 and prior)
* Mobile Forces (build 20000 and prior)
* Nerf Arena Blast (build 1.2 and prior)
* Postal 2 (build 1337 and prior)
* Rune (build 107 and prior)
* Tactical Ops (build 3.4.0 and prior)
* TNN Pro Hunter
* Unreal 1 (build 226f and prior)
* Unreal II XMP (build 7710 and prior)
* Unreal Tournament (build 451b and prior)
* Unreal Tournament 2003 (build 2225 and prior)
* Unreal Tournament 2004 (prior to build 3236)
* Wheel of Time (build 333b and prior)
* X-com Enforcer
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|