Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-5248

Опубликовано: 06 окт. 2007
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in (1) a PB_Y packet to the YPG server or (2) a PB_U packet to UCON. NOTE: this issue might be in Punkbuster itself, but there are insufficient details to be certain.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:id_software:doom_3:*:*:*:*:*:*:*:*
Версия до 1.3.1 (включая)
cpe:2.3:a:id_software:quake_4:*:*:*:*:*:*:*:*
Версия до 1.4.2 (включая)
cpe:2.3:a:take2games:prey:*:*:*:*:*:*:*:*
Версия до 1.3 (включая)

EPSS

Процентиль: 92%
0.07808
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-134

Связанные уязвимости

github
почти 4 года назад

Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in (1) a PB_Y packet to the YPG server or (2) a PB_U packet to UCON. NOTE: this issue might be in Punkbuster itself, but there are insufficient details to be certain.

EPSS

Процентиль: 92%
0.07808
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-134