CVE-2007-5250
Summary
| CVE | CVE-2007-5250 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-10-06 17:17:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The Windows dedicated server for the Unreal engine, as used by America's Army and America's Army Special Forces 2.8.2 and earlier, when Punkbuster (PB) is enabled, allows remote attackers to cause a denial of service (server hang) via packets containing 0x07 characters or other unspecified invalid characters. NOTE: this issue may overlap CVE-2007-4443. NOTE: this issue might be in Punkbuster itself, but there are insufficient details to be certain. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:M/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Americasarmy | Americas Army | All | All | All | All |
| Application | Americasarmy | Americas Army Special Forces | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| aluigi.altervista.org/adv/aaboompb-adv.txt | af854a3a-2127-422b-91ae-364da2661108 | aluigi.altervista.org | Exploit |
| Luigi Auriemma | af854a3a-2127-422b-91ae-364da2661108 | aluigi.org | Exploit |
| SecurityReason - Unexploitable buffer-overflow in America's Army 2.8.2 through PB | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| America's Army Special Forces Unreal Engine Denial Of Service - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.