Vulnerabilities > CVE-2003-1432 - Numeric Errors vulnerability in Epic Games Unreal Engine and Unreal Tournament 2003

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via (1) a packet with a negative size value, which is treated as a large positive number during memory allocation, or (2) a negative size value in a package file.

Common Weakness Enumeration (CWE)

Nessus

NASL familyGain a shell remotely
NASL idUNREAL_GAME_ENGINE.NASL
descriptionThe Unreal Engine in use on the remote game server is vulnerable to various attacks that may allow an attacker to use it as a distributed denial of service source or to execute arbitrary code on this host. Note that Nessus appears to have disabled this service while testing for these flaws.
last seen2020-06-01
modified2020-06-02
plugin id11228
published2003-02-12
reporterThis script is Copyright (C) 2003-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/11228
titleUnreal Engine Multiple Remote Vulnerabilities