F.E.A.R. (First Encounter Assault Recon) PunkBuster format string
| fear-punkbuster-format-string (36900) |
Description:
F.E.A.R. (First Encounter Assault Recon) could allow a remote attacker to execute arbitrary code on the system, caused by a format string vulnerability when handling PunkBuster packets in the game console. If PunkBuster is enabled, a remote attacker could send specially-crafted PB_Y or PB_U packets containing format string specifiers to exploit this vulnerability and execute arbitrary code on the system.
Platforms Affected:
- Monolith Productions, F.E.A.R. (First Encounter Assault Recon) 1.08 and prior
Remedy:
No remedy available as of July 4, 2009.
Consequences:
Gain Access
References:
- F.E.A.R. Web site, F.E.A.R. (First Encounter Assault Recon) at http://www.whatisfear.com/.
- Full-Disclosure Mailing List, Mon Oct 01 2007 - 14:31:43 CDT, Format string in F.E.A.R. 1.08 through PB at http://archives.neohapsis.com/archives/fulldisclosure/2007-10/0007.html.
- CVE-2007-5247: Multiple format string vulnerabilities in the Monolith Lithtech engine, as used by First Encounter Assault Recon (F.E.A.R.) 1.08 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in (1) a PB_Y packet to the YPG server on UDP port 27888 or (2) a PB_U packet to UCON on UDP port 27888, different vectors than CVE-2004-1500. NOTE: this issue might be in Punkbuster itself, but there are insufficient details to be certain.
Reported:
Oct 01, 2007
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
