Unreal Engine UGameEngine::UpdateConnectingMessage() buffer overflow
|unrealengine-ugameengineupdate-bo (60142)||High Risk|
Unreal Engine is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the UGameEngine::UpdateConnectingMessage() function. By persuading a victim to connect to a malicious server, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
No remedy available as of June 1, 2013.
- Luigi Auriemma Advisory, 06 Jul 2010: Clients unicode buffer-overflow in Unreal engine 2.5.
- Unreal Technology Web site: Unreal engine.
- BID-41424: Unreal Engine 'UpdateConnectingMessage()' Remote Stack Buffer Overflow Vulnerability
- CVE-2010-2702: Buffer overflow in the UGameEngine::UpdateConnectingMessage function in the Unreal engine 1, 2, and 2.5, as used in multiple games including Unreal Tournament 2004, Unreal tournament 2003, Postal 2, Raven Shield, and SWAT4, when downloads are enabled, allows remote attackers to execute arbitrary code via a long LEVEL field in a WELCOME response to a download request.
- OSVDB ID: 66039: Unreal Engine Multiple Product UGameEngine::UpdateConnectingMessage() Function Remote Overflow
- SA40466: Unreal Engine UGameEngine::UpdateConnectingMessage() Buffer Overflow
- Epic Games Unreal Engine 2
- Epic Games Unreal Engine 2.5
- Epic Games Unreal Tournament 3 1.3
- Epic Games Unreal Tournament 2003
- Epic Games Unreal Tournament 2004 3369
- Epic Games Unreal Tournament 2004
- Whiptail Interactive Postal 2
Jul 06, 2010
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email ignore thisxforceignore this@ignore thisus.ignore thisibm.comignore this