Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via (1) a packet with a negative size value, which is treated as a large positive number during memory allocation, or (2) a negative size value in a package file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Unreal_engine | Epic_games | 226f (including) | 226f (including) |
Unreal_engine | Epic_games | 433 (including) | 433 (including) |
Unreal_engine | Epic_games | 436 (including) | 436 (including) |
Unreal_tournament_2003 | Epic_games | 2199_linux (including) | 2199_linux (including) |
Unreal_tournament_2003 | Epic_games | 2199_win32 (including) | 2199_win32 (including) |
Unreal_tournament_2003 | Epic_games | demo_version_2206_linux (including) | demo_version_2206_linux (including) |
Unreal_tournament_2003 | Epic_games | demo_version_2206_win32 (including) | demo_version_2206_win32 (including) |