CVE-2008-3396: Input Validation
Published Jul 31, 2008
·Updated
Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain sequence of malformed packets.
Affected Software
3 affected components
Epic Games Unreal Tournament 2004=3334
Epic Games Unreal Tournament 2004<=3369
Epic Games Unreal Tournament 2004=3120
Event History
Jul 31, 2008
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3396?
CVE-2008-3396 is considered a high-severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2008-3396?
To mitigate CVE-2008-3396, upgrade to Unreal Tournament 2004 version 3369 or later, or apply any available patches.
3
What types of attacks are possible with CVE-2008-3396?
CVE-2008-3396 allows remote attackers to disrupt service by exploiting a NULL pointer dereference vulnerability.
4
Which versions of Unreal Tournament 2004 are affected by CVE-2008-3396?
CVE-2008-3396 affects Unreal Tournament 2004 versions up to and including 3369, as well as version 3120.
5
Can CVE-2008-3396 be exploited remotely?
Yes, CVE-2008-3396 can be exploited remotely through the sending of malformed packets.