CVE-2004-0608 (CNNVD-200412-011)
中文标题:
Epic Games Unreal Engine Secure Query缓冲区溢出漏洞
英文标题:
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces...
漏洞描述
中文描述:
Unreal引擎是一款被很多游戏使用的网络游戏引擎。 Unreal引擎在处理游戏请求时存在漏洞,远程攻击者可能利用此漏洞在游戏服务器上执行任意指令或导致拒绝服务。 Unreal引擎对畸形的带超长参数的GameSpy 'secure'请求未能做正确的处理,远程攻击者通过超长的请求导致内存破坏,可能执行任意指令。
英文描述:
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b and earlier, Unreal Tournament 2003 2225 and earlier, Unreal Tournament 2004 before 3236, Wheel of Time 333b and earlier, and X-com Enforcer, allows remote attackers to execute arbitrary code via a UDP packet containing a secure query with a long value, which overwrites memory.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| arush | devastation | 390.0 | - | - |
cpe:2.3:a:arush:devastation:390.0:*:*:*:*:*:*:*
|
| dreamforge | tnn_outdoors_pro_hunter | * | - | - |
cpe:2.3:a:dreamforge:tnn_outdoors_pro_hunter:*:*:*:*:*:*:*:*
|
| epic_games | unreal_engine | 226f | - | - |
cpe:2.3:a:epic_games:unreal_engine:226f:*:*:*:*:*:*:*
|
| epic_games | unreal_engine | 433 | - | - |
cpe:2.3:a:epic_games:unreal_engine:433:*:*:*:*:*:*:*
|
| epic_games | unreal_engine | 436 | - | - |
cpe:2.3:a:epic_games:unreal_engine:436:*:*:*:*:*:*:*
|
| epic_games | unreal_tournament | 451b | - | - |
cpe:2.3:a:epic_games:unreal_tournament:451b:*:*:*:*:*:*:*
|
| epic_games | unreal_tournament_2003 | 2199_linux | - | - |
cpe:2.3:a:epic_games:unreal_tournament_2003:2199_linux:*:*:*:*:*:*:*
|
| epic_games | unreal_tournament_2003 | 2199_macos | - | - |
cpe:2.3:a:epic_games:unreal_tournament_2003:2199_macos:*:*:*:*:*:*:*
|
| epic_games | unreal_tournament_2003 | 2199_win32 | - | - |
cpe:2.3:a:epic_games:unreal_tournament_2003:2199_win32:*:*:*:*:*:*:*
|
| epic_games | unreal_tournament_2003 | 2225_macos | - | - |
cpe:2.3:a:epic_games:unreal_tournament_2003:2225_macos:*:*:*:*:*:*:*
|
| epic_games | unreal_tournament_2003 | 2225_win32 | - | - |
cpe:2.3:a:epic_games:unreal_tournament_2003:2225_win32:*:*:*:*:*:*:*
|
| epic_games | unreal_tournament_2004 | macos | - | - |
cpe:2.3:a:epic_games:unreal_tournament_2004:macos:*:*:*:*:*:*:*
|
| epic_games | unreal_tournament_2004 | win32 | - | - |
cpe:2.3:a:epic_games:unreal_tournament_2004:win32:*:*:*:*:*:*:*
|
| infogrames | tacticalops | 3.4 | - | - |
cpe:2.3:a:infogrames:tacticalops:3.4:*:*:*:*:*:*:*
|
| infogrames | x-com_enforcer | * | - | - |
cpe:2.3:a:infogrames:x-com_enforcer:*:*:*:*:*:*:*:*
|
| ion_storm | deusex | 1.112_fm | - | - |
cpe:2.3:a:ion_storm:deusex:1.112_fm:*:*:*:*:*:*:*
|
| nerf_arena_blast | nerf_arena_blast | 1.2 | - | - |
cpe:2.3:a:nerf_arena_blast:nerf_arena_blast:1.2:*:*:*:*:*:*:*
|
| rage_software | mobile_forces | 20000.0 | - | - |
cpe:2.3:a:rage_software:mobile_forces:20000.0:*:*:*:*:*:*:*
|
| robert_jordan | wheel_of_time | 333.0b | - | - |
cpe:2.3:a:robert_jordan:wheel_of_time:333.0b:*:*:*:*:*:*:*
|
| running_with_scissors | postal_2 | 1337 | - | - |
cpe:2.3:a:running_with_scissors:postal_2:1337:*:*:*:*:*:*:*
|
| gentoo | linux | 1.4 | - | - |
cpe:2.3:o:gentoo:linux:1.4:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
exploitdb
exploitdb
cve.org
exploitdb
exploitdb
exploitdb
exploitdb
CVSS评分详情
AV:N/AC:L/Au:N/C:C/I:C/A:C
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2004-0608 |
2025-11-11 15:17:29 | 2025-11-11 07:32:21 |
| NVD | nvd_CVE-2004-0608 |
2025-11-11 14:50:55 | 2025-11-11 07:41:07 |
| CNNVD | cnnvd_CNNVD-200412-011 |
2025-11-11 15:08:44 | 2025-11-11 07:48:54 |
| EXPLOITDB | exploitdb_EDB-10032 |
2025-11-11 15:05:26 | 2025-11-11 08:00:24 |
| EXPLOITDB | exploitdb_EDB-16693 |
2025-11-11 15:05:58 | 2025-11-11 08:11:09 |
| EXPLOITDB | exploitdb_EDB-16848 |
2025-11-11 15:05:26 | 2025-11-11 08:11:15 |
版本与语言
安全公告
变更历史
查看详细变更
- references_count: 10 -> 12
查看详细变更
- references_count: 8 -> 10
- tags_count: 4 -> 6
查看详细变更
- references_count: 5 -> 8
- tags_count: 0 -> 4
- data_sources: ['cnnvd', 'cve', 'nvd'] -> ['cnnvd', 'cve', 'exploitdb', 'nvd']
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-200412-011
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.CRITICAL
- cvss_score: 未提取 -> 10.0
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:L/Au:N/C:C/I:C/A:C
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 21
- data_sources: ['cve'] -> ['cve', 'nvd']