Lucene search

K
cveMitreCVE-2008-6441
HistoryMar 09, 2009 - 2:30 p.m.

CVE-2008-6441

2009-03-0914:30:00
CWE-134
mitre
web.nvd.nist.gov
35
epic games
unreal engine
cve-2008-6441
format string vulnerability
remote code execution

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

High

EPSS

0.003

Percentile

66.3%

Format string vulnerability in the Epic Games Unreal engine client, as used in multiple games, allows remote servers to execute arbitrary code via (1) the CLASS parameter in a DLMGR command, (2) a malformed package (PKG), and possibly (3) the LEVEL parameter in a WELCOME command.

Affected configurations

Nvd
Node
epicgamesunreal_engineMatch2
OR
epicgamesunreal_engineMatch2.5
OR
epicgamesunreal_engineMatch3
VendorProductVersionCPE
epicgamesunreal_engine2cpe:2.3:a:epicgames:unreal_engine:2:*:*:*:*:*:*:*
epicgamesunreal_engine2.5cpe:2.3:a:epicgames:unreal_engine:2.5:*:*:*:*:*:*:*
epicgamesunreal_engine3cpe:2.3:a:epicgames:unreal_engine:3:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

High

EPSS

0.003

Percentile

66.3%

Related for CVE-2008-6441