Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via (1) a packet with a negative size value, which is treated as a large positive number during memory allocation, or (2) a negative size value in a package file.
2003-12-31T05:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | epic_games | unreal_engine | 226f | Yes |
Application | epic_games | unreal_engine | 433 | Yes |
Application | epic_games | unreal_engine | 436 | Yes |
Application | epic_games | unreal_tournament_2003 | 2199_linux | Yes |
Application | epic_games | unreal_tournament_2003 | 2199_win32 | Yes |
Application | epic_games | unreal_tournament_2003 | demo_version_2206_linux | Yes |
Application | epic_games | unreal_tournament_2003 | demo_version_2206_win32 | Yes |