CVE-2004-0608
Summary
| CVE | CVE-2004-0608 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-06 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b and earlier, Unreal Tournament 2003 2225 and earlier, Unreal Tournament 2004 before 3236, Wheel of Time 333b and earlier, and X-com Enforcer, allows remote attackers to execute arbitrary code via a UDP packet containing a secure query with a long value, which overwrites memory. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Arush | Devastation | 390.0 | All | All | All |
| Application | Dreamforge | Tnn Outdoors Pro Hunter | All | All | All | All |
| Application | Epic Games | Unreal Engine | 226f | All | All | All |
| Application | Epic Games | Unreal Engine | 433 | All | All | All |
| Application | Epic Games | Unreal Engine | 436 | All | All | All |
| Application | Epic Games | Unreal Tournament | 451b | All | All | All |
| Application | Epic Games | Unreal Tournament 2003 | 2199_linux | All | All | All |
| Application | Epic Games | Unreal Tournament 2003 | 2199_macos | All | All | All |
| Application | Epic Games | Unreal Tournament 2003 | 2199_win32 | All | All | All |
| Application | Epic Games | Unreal Tournament 2003 | 2225_macos | All | All | All |
| Application | Epic Games | Unreal Tournament 2003 | 2225_win32 | All | All | All |
| Application | Epic Games | Unreal Tournament 2004 | macos | All | All | All |
| Application | Epic Games | Unreal Tournament 2004 | win32 | All | All | All |
| Operating System | Gentoo | Linux | 1.4 | All | All | All |
| Application | Infogrames | Tacticalops | 3.4 | All | All | All |
| Application | Infogrames | X-com Enforcer | All | All | All | All |
| Application | Ion Storm | Deusex | 1.112_fm | All | All | All |
| Application | Nerf Arena Blast | Nerf Arena Blast | 1.2 | All | All | All |
| Application | Rage Software | Mobile Forces | 20000.0 | All | All | All |
| Application | Robert Jordan | Wheel Of Time | 333.0b | All | All | All |
| Application | Running With Scissors | Postal 2 | 1337 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Epic Games Unreal Engine Memory Corruption Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Vendor Advisory |
| Gentoo Linux Documentation -- Unreal Tournament 2003/2004: Buffer overflow in 'secure' queries | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | Patch, Vendor Advisory |
| 'Code execution in the Unreal Engine through \secure\ packet' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| aluigi.altervista.org/adv/unsecure-adv.txt | af854a3a-2127-422b-91ae-364da2661108 | aluigi.altervista.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.