CVE-2004-2371
Multiple Red Storm web-based games, including Ghost Recon 1.4 and earlier, Desert Siege, and The Sum of all Fears 1.1.1.0 and earlier, do not properly check return values from certain functions, which allows remote attackers to cause a denial of service…
Does this matter?
Lower severity and a low EPSS score (3.34%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple Red Storm web-based games, including Ghost Recon 1.4 and earlier, Desert Siege, and The Sum of all Fears 1.1.1.0 and earlier, do not properly check return values from certain functions, which allows remote attackers to cause a denial of service (hang) via packets that contain text strings with incorrect size values.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 3.34% probability · 88th percentile
- CISA KEV
- Not listed
- Affected
- redstorm/desert siege · redstorm/ghost recon · redstorm/the sum of all fears
- Source
- cve@mitre.org
References
- http://aluigi.altervista.org/adv/grboom-adv.txtExploit
- http://www.securityfocus.com/archive/1/355051Exploit
- http://www.securityfocus.com/bid/9738
- http://www.zone-h.org/advisories/read/id=4038Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15305
- http://aluigi.altervista.org/adv/grboom-adv.txtExploit
- http://www.securityfocus.com/archive/1/355051Exploit
- http://www.securityfocus.com/bid/9738
- http://www.zone-h.org/advisories/read/id=4038Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15305
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.