First published: Fri Dec 31 2004(Updated: )
Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in class names.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Epic Games Unreal Engine | =436 | |
Epic Games Unreal Engine | =226f | |
Epic Games Unreal Engine | =433 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2004-1805 is considered high due to its potential to cause a denial of service and execute arbitrary code.
To fix CVE-2004-1805, ensure that you are using an updated version of the Unreal Engine that addresses this format string vulnerability.
CVE-2004-1805 affects games using Epic Games Unreal Engine versions 436, 226f, and 433.
CVE-2004-1805 is caused by improper handling of format string specifiers in class names within the affected Unreal Engine versions.
Yes, CVE-2004-1805 can potentially allow remote attackers to execute arbitrary code by exploiting the format string vulnerability.