Lucene search

K
cveMitreCVE-2007-5247
HistoryOct 06, 2007 - 5:17 p.m.

CVE-2007-5247

2007-10-0617:17:00
CWE-134
mitre
web.nvd.nist.gov
17
cve
2007
5247
format string
vulnerabilities
monolith
lithtech
f.e.a.r.
punkbuster
pb
remote attackers
arbitrary code
denial of service
udp port
vector

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.019

Percentile

88.9%

Multiple format string vulnerabilities in the Monolith Lithtech engine, as used by First Encounter Assault Recon (F.E.A.R.) 1.08 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in (1) a PB_Y packet to the YPG server on UDP port 27888 or (2) a PB_U packet to UCON on UDP port 27888, different vectors than CVE-2004-1500. NOTE: this issue might be in Punkbuster itself, but there are insufficient details to be certain.

Affected configurations

Nvd
Node
monolith_productionsfirst_encounter_assault_reconRange1.08
VendorProductVersionCPE
monolith_productionsfirst_encounter_assault_recon*cpe:2.3:a:monolith_productions:first_encounter_assault_recon:*:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.019

Percentile

88.9%

Related for CVE-2007-5247