Advertisement
Promo

Security threats Toolkit

'Unreal' critical flaw lets in attackers

David Becker CNET News

Published: 23 Jun 2004 09:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A security researcher warned on Tuesday of a "critical" flaw in a widely used piece of game software that could let attackers take over vulnerable PCs.

Security company Secunia issued a bulletin warning of the flaw in some versions of the "Unreal" game engine, used by numerous PC games. Most game publishers using the engine have already issued patches, however, to plug the hole.

According to the bulletin, malicious hackers could send a string of junk data to the security tool the Unreal engine uses to verify online game servers. Once the security tool was comprised by such a "buffer overrun," the attacker would be able to execute code at will on the machine.

Games affected by the flaw include five versions of "Unreal," all of which are secured by patches released last week, plus shooting games "Postal 2" and "Deus Ex," also fixed by recent patches.

The flaw was discovered by independent security researcher Luigi Auriemma, whose work has played a major role in publicising online gaming as a possible vector for security threats. Auriemma discovered several flaws in software used by GameSpy, a popular online game-hosting service, and fought with the company to publicise the holes.

As they develop more online capabilities, games have become an increasingly popular avenue for online miscreants. A recently patched flaw in the shooting game "Half-Life" and its popular online offshoots opened a door for denial-of-service attacks, while the GameSpy service and software have been the subject of several security alerts.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
122 out of 196 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters