Epic Games Unreal Engine Multiple Format String Vulnerabilities
BID:31141
Info
Epic Games Unreal Engine Multiple Format String Vulnerabilities
| Bugtraq ID: | 31141 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6441 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 11 2008 12:00AM |
| Updated: | May 07 2015 05:24PM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
Epic Games Unreal Engine 436 Epic Games Unreal Engine 3 Epic Games Unreal Engine 226f |
| Not Vulnerable: | |
Discussion
Epic Games Unreal Engine Multiple Format String Vulnerabilities
Unreal Engine is prone to multiple remote format-string vulnerabilities.
Attackers can exploit the issues to execute arbitrary code within the context of a client application that uses the vulnerable engine.
Unreal Engine is prone to multiple remote format-string vulnerabilities.
Attackers can exploit the issues to execute arbitrary code within the context of a client application that uses the vulnerable engine.
Exploit / POC
Epic Games Unreal Engine Multiple Format String Vulnerabilities
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
Epic Games Unreal Engine Multiple Format String Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Epic Games Unreal Engine Multiple Format String Vulnerabilities
References:
References:
- Unreal Engine Homepage (Epic Games)
- Clients format strings in the Unreal engine (Luigi Auriemma
)