CVE-2004-1395
Summary
| CVE | CVE-2004-1395 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The Lithtech engine, as used in (1) Contract Jack 1.1 and earlier, (2) No one lives forever 2 1.3 and earlier, (3) Tron 2.0 1.042 and earlier, (4) F.E.A.R. (First Encounter Assault and Recon), and possibly other games, allows remote attackers to cause a denial of service (connection refused) via a UDP packet that causes recvfrom to generate a return code that causes the listening loop to exit, as demonstrated using zero byte packets or packets between 8193 and 12280 bytes, which result in conditions that are not "Operation would block." |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Monolith Productions | Contract Jack | 1.1 | All | All | All |
| Application | Monolith Productions | No One Lives Forever 2 | 1.0.004 | All | All | All |
| Application | Monolith Productions | No One Lives Forever 2 | 1.3 | All | All | All |
| Application | Monolith Productions | Tron | 2.0.1.0 | All | All | All |
| Application | Monolith Productions | Tron | 2.0.1.42 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Monolith Lithtech Game Engine Remote Denial Of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| 'Socket unreacheable in the Lithtech engine (new protocol)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Secunia - Advisories - Lithtech Engine UDP Datagram Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| [Full-Disclosure] Socket unreacheable in the Lithtech engine (new protocol) | af854a3a-2127-422b-91ae-364da2661108 | lists.grok.org.uk | Exploit, Patch |
| aluigi.altervista.org/adv/lithsock-adv.txt | af854a3a-2127-422b-91ae-364da2661108 | aluigi.altervista.org | Exploit, Patch |
| Secunia - Advisories - F.E.A.R. Lithtech Engine Denial of Service and Format String Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [Full-disclosure] F.E.A.R. 1.01 likes lithsock | af854a3a-2127-422b-91ae-364da2661108 | lists.grok.org.uk | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.