HIGH · 9.3

CVE-2007-5248

Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3 and earlier, when Punkbuster (PB) is enabled, allo...

Vulnerability Description

Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in (1) a PB_Y packet to the YPG server or (2) a PB_U packet to UCON. NOTE: this issue might be in Punkbuster itself, but there are insufficient details to be certain.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Id SoftwareDoom 3<= 1.3.1
Id SoftwareQuake 4<= 1.4.2
Take2GamesPrey<= 1.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-5248?

CVE-2007-5248 is a vulnerability with a CVSS score of 9.3 (HIGH). Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3 and earlier, when Punkbuster (PB) is enabled, allo...

How severe is CVE-2007-5248?

CVE-2007-5248 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-5248?

Check the references section above for vendor advisories and patch information. Affected products include: Id Software Doom 3, Id Software Quake 4, Take2Games Prey.