CVE-2007-5249

Multiple buffer overflows in the logging function in the Unreal engine, as used by America's Army and America's Army Special Forces 2.8.2 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to cause a denial of service (daemon crash) via a long (1) PB_Y packet to the YPG server on UDP port 1716 or (2) PB_U packet to UCON on UDP port 1716, different vectors than CVE-2007-4442. NOTE: this issue might be in Punkbuster itself, but there are insufficient details to be certain.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:americasarmy:america\'s_army:*:*:*:*:*:*:*:*
cpe:2.3:a:americasarmy:america\'s_army_special_forces:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:37

Type Values Removed Values Added
References () http://aluigi.altervista.org/adv/aaboompb-adv.txt - Exploit () http://aluigi.altervista.org/adv/aaboompb-adv.txt - Exploit
References () http://aluigi.org/poc/aaboompb.zip - Exploit () http://aluigi.org/poc/aaboompb.zip - Exploit
References () http://secunia.com/advisories/27015 - Vendor Advisory () http://secunia.com/advisories/27015 - Vendor Advisory
References () http://securityreason.com/securityalert/3193 - () http://securityreason.com/securityalert/3193 -
References () http://www.securityfocus.com/archive/1/481227/100/0/threaded - () http://www.securityfocus.com/archive/1/481227/100/0/threaded -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/36897 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/36897 -

Information

Published : 2007-10-06 17:17

Updated : 2024-11-21 00:37


NVD link : CVE-2007-5249

Mitre link : CVE-2007-5249

CVE.ORG link : CVE-2007-5249


JSON object : View

Products Affected

americasarmy

  • america\'s_army_special_forces
  • america\'s_army
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer