First published: Fri Dec 31 2004(Updated: )
Directory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in a UMOD (Unreal MOD) file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Unreal Engine | =433 | |
Unreal Engine | =436 | |
Unreal Tournament | =451b | |
Unreal Tournament | =2199_macos | |
Unreal Tournament | =2199_win32 | |
Unreal Tournament | =2225_macos | |
Unreal Tournament | =2225_win32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1958 is classified as a high severity vulnerability due to its potential for remote file overwriting.
To fix CVE-2004-1958, ensure that you update to a patched version of the affected software from Epic Games.
CVE-2004-1958 affects multiple versions of Unreal Engine and Unreal Tournament 2003, including specific OS versions.
Yes, CVE-2004-1958 can be exploited remotely by attackers using crafted UMOD files.
CVE-2004-1958 is a directory traversal vulnerability that enables attackers to access arbitrary files.