Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

APP:GAME:UNREAL-GAMESPY-QP-BOF

Severity

High

Recommended

No

Recommended Action

Drop

Category

APP

Keywords

Unreal Gamespy Query Protocol Buffer Overflow

Release Date

2004/06/23

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

APP: Unreal Gamespy Query Protocol Buffer Overflow


This signature detects attempts to exploit a known vulnerability against the GameSpy query protocol supported by Unreal game engine. Attackers can crash a game server running the Unreal game engine, or execute arbitrary code with permissions of the user running the server.

Extended Description

Unreal Engine is reportedly prone to a memory corruption vulnerability. This issue presents itself when a remote attacker sends an excessive value to a vulnerable game server through a '\secure\' query. An attacker can exploit this issue to potentially overwrite sensitive memory addresses leading to a variety of attacks including denial of service and possible remote code execution.

Affected Products

  • ARUSH Devastation 390.0.0
  • DreamForge TNN Outdoors Pro Hunter
  • Epic Games Unreal Engine 226f
  • Epic Games Unreal Engine 3
  • Epic Games Unreal Engine 436
  • Epic Games Unreal Tournament 2003 2199 linux
  • Epic Games Unreal Tournament 2003 2199 macOS
  • Epic Games Unreal Tournament 2003 2199 win32
  • Epic Games Unreal Tournament 2003 2225 macOS
  • Epic Games Unreal Tournament 2003 2225 win32
  • Epic Games Unreal Tournament 2004 macOS
  • Epic Games Unreal Tournament 2004 win32
  • Epic Games Unreal Tournament 3 1.3beta4
  • Gentoo Linux 1.4.0
  • Infogrames TacticalOps 3.4.0
  • Infogrames X-com Enforcer
  • Ion Storm DeusEx 1.112.0 fm
  • Nerf Arena Blast 1.2.0
  • Rage Software Mobile Forces 20000.0.0
  • Robert Jordan Wheel of Time 333.0.0 b
  • Running With Scissors Postal 2 1337

References

  • BugTraq: 10570
  • CVE: CVE-2004-0608
  • URL: http://aluigi.altervista.org/papers/gsmsalg.h
  • URL: http://archives.neohapsis.com/archives/bugtraq/2004-06/0335.html

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out