>> Unreal Tournament 3 Memory Corruption and DoS Vulnerabilities
Title : Unreal Tournament 3 Memory Corruption and DoS Vulnerabilities VUPEN ID : VUPEN/ADV-2008-2260 CVE ID : CVE-2008-3409 - CVE-2008-3410 CWE ID : CWE-119 - CWE-476
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-07-31
Technical Description
Two vulnerabilities have been identified in Unreal Tournament 3, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system.
The first issue is caused by a memory corruption when processing user-supplied packets, which could be exploited to crash an affected server or execute arbitrary code.
The second vulnerability is caused by a NULL pointer dereference error when processing malformed data, which could be exploited by remote attackers to crash a vulnerable server, creating a denial of service condition.