CVE-2007-5248
Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.48%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in (1) a PB_Y packet to the YPG server or (2) a PB_U packet to UCON. NOTE: this issue might be in Punkbuster itself, but there are insufficient details to be certain.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 7.48% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-134
- Affected
- id software/doom 3 · id software/quake 4 · take2games/prey
- Source
- cve@mitre.org
References
- http://aluigi.altervista.org/adv/d3engfspb-adv.txtExploit
- http://aluigi.org/poc/d3engfspb.zipExploit
- http://secunia.com/advisories/27002Vendor Advisory
- http://secunia.com/advisories/27023Vendor Advisory
- http://secunia.com/advisories/27036Vendor Advisory
- http://securityreason.com/securityalert/3196
- http://www.securityfocus.com/archive/1/481229/100/0/threaded
- http://www.securityfocus.com/bid/25893
- http://www.vupen.com/english/advisories/2007/3333
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36899
- http://aluigi.altervista.org/adv/d3engfspb-adv.txtExploit
- http://aluigi.org/poc/d3engfspb.zipExploit
- http://secunia.com/advisories/27002Vendor Advisory
- http://secunia.com/advisories/27023Vendor Advisory
- http://secunia.com/advisories/27036Vendor Advisory
- http://securityreason.com/securityalert/3196
- http://www.securityfocus.com/archive/1/481229/100/0/threaded
- http://www.securityfocus.com/bid/25893
- http://www.vupen.com/english/advisories/2007/3333
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36899
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.