VDB
CVE-2007-4442
CVE-2007-4442
PUBLISHED
CVSS 5 MEDIUM
Stack-based buffer overflow in the logging function in the Unreal engine, possibly 2003 and 2004, as used in the internal web server, allows remote attackers to cause a denial of service (application crash) via a request for a long .gif filename in the images/ directory, related to conversion from Unicode to ASCII.
EPSS 12.20% · 94.0th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
12.20%
94.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| epic_games | unreal_engine | 2003, 2004 |
| n/a | n/a | * |
Timeline
- Aug 21, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Apr 5, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- unreal-logging-bo(36102) vdb
- 20070818 Unexploitable buffer-overflow in the logging function of the Unreal engine mailing-list
- 26506 third-party-advisory
- 3039 third-party-advisory
- 25374 vdb
- http://aluigi.org/poc/unrwebdos.zip url
- http://aluigi.org/adv/unrwebdos-adv.txt url
- https://nvd.nist.gov/vuln/detail/CVE-2007-4442 advisory