MEDIUM · 5.0

CVE-2004-0278

Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet t...

Vulnerability Description

Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet that specifies the length of data to read and then sends a second TCP packet that contains less data than specified, which causes Ratbag to repeatedly check the socket for more data.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
RatbagDirt Track Racing1.0.3
RatbagDirt Track Racing AustraliaAll versions
RatbagDirt Track Racing Sprint CarsAll versions
RatbagLeadfootAll versions
RatbagWorld Of Outlaws Sprint CarsAll versions

References

FAQ

What is CVE-2004-0278?

CVE-2004-0278 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet t...

How severe is CVE-2004-0278?

CVE-2004-0278 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0278?

Check the references section above for vendor advisories and patch information. Affected products include: Ratbag Dirt Track Racing, Ratbag Dirt Track Racing Australia, Ratbag Dirt Track Racing Sprint Cars, Ratbag Leadfoot, Ratbag World Of Outlaws Sprint Cars.