Epic Games Unreal Engine Client Unreal URL服务拒绝漏洞

Epic Games Unreal Engine Client Unreal URL服务拒绝漏洞

漏洞ID 1107186 漏洞类型 缓冲区溢出
发布时间 2003-02-05 更新时间 2003-12-31
图片[1]-Epic Games Unreal Engine Client Unreal URL服务拒绝漏洞-安全小百科CVE编号 CVE-2003-1431
图片[2]-Epic Games Unreal Engine Client Unreal URL服务拒绝漏洞-安全小百科CNNVD-ID CNNVD-200312-405
漏洞平台 Multiple CVSS评分 7.1
|漏洞来源
https://www.exploit-db.com/exploits/22223
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200312-405
|漏洞详情
EpicGamesUnrealEngine226f至436版本存在缓冲区溢出漏洞。远程攻击者可以借助UnrealURL中的超长主机字符串导致服务拒绝(崩溃)。
|漏洞EXP
source: http://www.securityfocus.com/bid/6774/info

t has been reported that a memory corruption bug exists in games based on the Unreal Engine. Under some circumstances, when the game client connects to a server using a excessive length Unreal URL it may be possible for the malformed URL to write over sensitive areas of stack memory causing the client to crash.

unreal://(261 chars)[EIP_byte2][EIP_byte1]
unreal://(258 chars)
|参考资料

来源:XF
名称:ut-url-memory-corruption(11301)
链接:http://xforce.iss.net/xforce/xfdb/11301
来源:BID
名称:6774
链接:http://www.securityfocus.com/bid/6774
来源:BUGTRAQ
名称:20030211Re:EpicGamesthreatenstosuesecurityresearchers
链接:http://archives.neohapsis.com/archives/bugtraq/2003-02/0142.html
来源:BUGTRAQ
名称:20030205Unrealengine:resultsofmyresearch
链接:http://archives.neohapsis.com/archives/bugtraq/2003-02/0063.html

相关推荐: Opera 7.0 – History Object Information Disclosure

Opera 7.0 – History Object Information Disclosure 漏洞ID 1053718 漏洞类型 发布时间 2003-02-04 更新时间 2003-02-04 CVE编号 N/A CNNVD-ID N/A 漏洞平台 Wi…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享