Lucene search

K
cveMitreCVE-2010-2702
HistoryJul 12, 2010 - 5:30 p.m.

CVE-2010-2702

2010-07-1217:30:03
CWE-119
mitre
web.nvd.nist.gov
26
cve-2010-2702
buffer overflow
ugameengine
updateconnectingmessage
unreal engine
remote code execution
download request

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.2

Confidence

High

EPSS

0.063

Percentile

93.7%

Buffer overflow in the UGameEngine::UpdateConnectingMessage function in the Unreal engine 1, 2, and 2.5, as used in multiple games including Unreal Tournament 2004, Unreal tournament 2003, Postal 2, Raven Shield, and SWAT4, when downloads are enabled, allows remote attackers to execute arbitrary code via a long LEVEL field in a WELCOME response to a download request.

Affected configurations

Nvd
Node
epicgamesunreal_engineMatch1
OR
epicgamesunreal_engineMatch2
OR
epicgamesunreal_engineMatch2.5
AND
epicgamespostal_2
OR
epicgamesraven_shield
OR
epicgamesswat_4
OR
epicgamesunreal_tournament_2003
OR
epicgamesunreal_tournament_2004
VendorProductVersionCPE
epicgamesunreal_engine1cpe:2.3:a:epicgames:unreal_engine:1:*:*:*:*:*:*:*
epicgamesunreal_engine2cpe:2.3:a:epicgames:unreal_engine:2:*:*:*:*:*:*:*
epicgamesunreal_engine2.5cpe:2.3:a:epicgames:unreal_engine:2.5:*:*:*:*:*:*:*
epicgamespostal_2*cpe:2.3:a:epicgames:postal_2:*:*:*:*:*:*:*:*
epicgamesraven_shield*cpe:2.3:a:epicgames:raven_shield:*:*:*:*:*:*:*:*
epicgamesswat_4*cpe:2.3:a:epicgames:swat_4:*:*:*:*:*:*:*:*
epicgamesunreal_tournament_2003*cpe:2.3:a:epicgames:unreal_tournament_2003:*:*:*:*:*:*:*:*
epicgamesunreal_tournament_2004*cpe:2.3:a:epicgames:unreal_tournament_2004:*:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.2

Confidence

High

EPSS

0.063

Percentile

93.7%

Related for CVE-2010-2702