Epic Games Unreal Tournament Server Engine远程格式串漏洞

Epic Games Unreal Tournament Server Engine远程格式串漏洞

漏洞ID 1107778 漏洞类型 格式化字符串
发布时间 2004-03-10 更新时间 2005-10-20
图片[1]-Epic Games Unreal Tournament Server Engine远程格式串漏洞-安全小百科CVE编号 CVE-2004-1805
图片[2]-Epic Games Unreal Tournament Server Engine远程格式串漏洞-安全小百科CNNVD-ID CNNVD-200412-268
漏洞平台 Multiple CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/23799
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200412-268
|漏洞详情
使用EpicGamesUnrealEngine436版本的游戏存在格式串漏洞。远程攻击者借助类名中的格式串说明符导致服务拒绝(崩溃)和可能的任意代码执行。
|漏洞EXP
source: http://www.securityfocus.com/bid/9840/info

A format string vulnerability has been reported to exists in the Unreal Tournament server engine. This issue is due to a failure of the server application to properly sanitize user supplied network data.

Ultimately this vulnerability could allow for execution of arbitrary code on the system implementing the affected server software, which would occur in the security context of the server process.

Example:

From:
Class=Engine.Pawn

To:
Class=%n%nEngine.Pawn

If the game is vulnerable it will crash when launched.
|参考资料

来源:BID
名称:9840
链接:http://www.securityfocus.com/bid/9840
来源:XF
名称:ut-class-format-string(15430)
链接:http://xforce.iss.net/xforce/xfdb/15430
来源:SECUNIA
名称:11108
链接:http://secunia.com/advisories/11108
来源:aluigi.altervista.org
链接:http://aluigi.altervista.org/adv/unrfs-adv.txt
来源:BUGTRAQ
名称:20040311Re:FormatstringbuginEpicGamesUnrealengine
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=107902755204583&w;=2
来源:BUGTRAQ
名称:20040310FormatstringbuginEpicGamesUnrealengine
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=107893764406905&w;=2

相关推荐: BroadVision One-To-One Enterprise漏洞

BroadVision One-To-One Enterprise漏洞 漏洞ID 1205940 漏洞类型 未知 发布时间 2001-02-16 更新时间 2001-02-16 CVE编号 CVE-2001-0031 CNNVD-ID CNNVD-200102…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享