• About Us
  • Search
  • Compatibility
  • Forums
  • Archive
  • Channels
  • Home
To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.
Warp2Search.net » News » March 2004 » Format String Bug in EpicGames Unreal engine

Format String Bug in EpicGames Unreal engine

Posted by: Newsfactory on: 03/11/2004 05:22 PM [ Print | 3 comment(s) ] · 3124 views

Security Focus reports that Luigi Auriemma found a bug in Epic's Unreal engine that was reported to EpicGames on 2th September 2003 and still nothing has been done about it! here's some of the games that are effected!

Unreal 1 Unreal II XMP Unreal Tournament Unreal Tournament 2003



Wheel of Time X-com Enforcer XIII Rainbow Six: Raven Shield Devastation DeusEx America's Army

The problem is a format string bug in the Classes management. Each time a client connects to a server it sends the names of the objects it uses (called classes).

If an attacker uses a class name containing format parameters (as %n, %s and so on) he will be able to crash or also to execute malicious code on the remote server.

Format String Bug in EpicGames Unreal engine


Digg it! Del.icio.us Technorati Furl Google Bookmarks

« Aliens vs. Predator · Format String Bug in EpicGames Unreal engine · InterVideo DVD Copy 2 Gold & Platinum »

Comment

vegetto34
Unregistered



#51870 Posted on: 03/11/2004 06:26 PM
LOL What an easy to exploit security hole. I might have some fun with this one.

"Yea uh... patch in 'two weeks'... "

Comment

Devourer
Unregistered



#51873 Posted on: 03/11/2004 07:18 PM
"was reported to EpicGames on 2th September 2003" That's the longest 2 weeks in history. :P

Comment

Chernobyl
Unregistered



Posts: 57
Joined: 2003-05-03

#51877 Posted on: 03/11/2004 09:25 PM
They need to be fined for this sort of conduct, and big fines too. Plain irresponsible!

Warp2Search.net » News » March 2004 » Format String Bug in EpicGames Unreal engine

Latest News

· Monitor Asset Manager 2.5
· Parted Magic 4.9
· PicPick 2.2.4
· ZipGenius 6.3.1.2520
· CDBurnerXP 4.3.0.1991
· FixWin 1.2
· Cobian Backup 10.0.0.521 Beta
· Glint 1.26 (Build 1019)
· Free Audio Converter 1.2.4.88
· System Explorer 2.1.3
· Google Chrome BETA 5.0.356.0
· Virus Effect Remover 3.2.2.26
· Speccy 1.00.125 Beta
· Dropbox 0.8.21 Experimental
· Cobian Backup 10.0.0.519 Beta
· ID3 Renamer 3.0.3
· FakeAlert Stinger 10.1.0.728
· Nvidia Forceware for Windows Vista\Win 7 197.13

Community Forum

· CD/DVD burning software
Posted by Philipp

· help Read/write GUID from registry
Posted by joshi

· How to use Driver Robot to update drivers?
Posted by necoleliao

· Scanning website files on the fly
Posted by Alan Connor

· Updated motherboard chipset - Net stopped working
Posted by Soaron


Nodes To Friends





Online Users

There are currently 469 user(s) online:
Ask Jeeves, Google, Live Search, MSN, Yahoo

© 2007-2009 Esselbach Internet Solutions
All products mentioned are registered trademarks or trademarks of their respective owners.
Read our disclaimer over here and our Privacy Policy over here
Managed with Contentteller(R) Business Edition, (C) 2002 - 2009 Esselbach Internet Solutions