Vulnerability Description
Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freeform Interactive | Purge Jihad | 2.2.1 |
| Monolith Productions | Alien Versus Predator | 2.1.0.9.6 |
| Monolith Productions | Blood | 2.2.1 |
| Monolith Productions | Contract Jack | 1.1 |
| Monolith Productions | Global Operations | 2.0 |
| Monolith Productions | Kiss Psycho Circus | 1.13 |
| Monolith Productions | Legends Of Might And Magic | 1.1 |
| Monolith Productions | No One Lives Forever | 1.0.004 |
| Monolith Productions | Sanity | 1.0 |
| Monolith Productions | Shogo | 2.2 |
| Monolith Productions | Tron | 2.0.1.42 |
References
- http://aluigi.altervista.org/adv/lithfs-adv.txt
- http://marc.info/?l=bugtraq&m=109969394601331&w=2
- http://secunia.com/advisories/13116/Vendor Advisory
- http://secunia.com/advisories/17317
- http://www.securityfocus.com/bid/11610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17972
- http://aluigi.altervista.org/adv/lithfs-adv.txt
- http://marc.info/?l=bugtraq&m=109969394601331&w=2
- http://secunia.com/advisories/13116/Vendor Advisory
- http://secunia.com/advisories/17317
- http://www.securityfocus.com/bid/11610
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17972
FAQ
What is CVE-2004-1500?
CVE-2004-1500 is a vulnerability with a CVSS score of 2.1 (LOW). Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a ...
How severe is CVE-2004-1500?
CVE-2004-1500 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-1500?
Check the references section above for vendor advisories and patch information. Affected products include: Freeform Interactive Purge Jihad, Monolith Productions Alien Versus Predator, Monolith Productions Blood, Monolith Productions Contract Jack, Monolith Productions Global Operations.