Unreal Engine Exploit & Patch Plans

A recently posted BugTraq listing (thanks 3DGPU) outlines a vulnerability in Epic's Unreal engine that's susceptible to DoS, DDoS and bounce attacks with spoofed UDP packets. The report outlines the problem, which affects dozens of games from Unreal through UT2003, and describes how the author of the report held off on publicizing this for almost three months to give time for Epic to devise a fix. I contacted Epic's Mark Rein to ask about this and he was very frank about how this had indeed been brought to their attention, but had unfortunately fallen through the cracks. He sent along a list of changes for the next planned UT2003 patch which will now address these vulnerabilities, and says it's likely that a small patch will be issued to address these in the original version of Unreal Tournament as well. As for other games using the Unreal engine, he says that fixes like this are always made available to licensees, who will then be able to issue patches of their own should they so choose. Here is Mark's no-holds-barred assessment of why this went unaddressed after being brought to their attention:
I won't sugar coat this. We f***ed up on this. Yes this is real and yes this was brought to our attention and yes we should have fixed it by now. We are working on fixing this now and we will have this fixed in an upcoming patch before too long.
View : : :
39.
 
Re: No subject
Feb 6, 2003, 19:03
39.
Re: No subject Feb 6, 2003, 19:03
Feb 6, 2003, 19:03
 
Anon = troll
Xombie x0mbie x0mb|e Xombie
Date
Subject
Author
1.
Feb 6, 2003Feb 6 2003
2.
Feb 6, 2003Feb 6 2003
3.
Feb 6, 2003Feb 6 2003
4.
Feb 6, 2003Feb 6 2003
5.
Feb 6, 2003Feb 6 2003
9.
Feb 6, 2003Feb 6 2003
10.
Feb 6, 2003Feb 6 2003
28.
Feb 6, 2003Feb 6 2003
11.
Feb 6, 2003Feb 6 2003
12.
Feb 6, 2003Feb 6 2003
13.
Feb 6, 2003Feb 6 2003
14.
Feb 6, 2003Feb 6 2003
15.
Feb 6, 2003Feb 6 2003
18.
Feb 6, 2003Feb 6 2003
19.
Feb 6, 2003Feb 6 2003
6.
Feb 6, 2003Feb 6 2003
7.
Feb 6, 2003Feb 6 2003
8.
Feb 6, 2003Feb 6 2003
16.
Feb 6, 2003Feb 6 2003
17.
Feb 6, 2003Feb 6 2003
20.
Feb 6, 2003Feb 6 2003
21.
Feb 6, 2003Feb 6 2003
22.
Feb 6, 2003Feb 6 2003
23.
Feb 6, 2003Feb 6 2003
   Re: eh...
24.
Feb 6, 2003Feb 6 2003
    VOTE
25.
Feb 6, 2003Feb 6 2003
    Re: eh...
26.
Feb 6, 2003Feb 6 2003
    Re: eh...
27.
Feb 6, 2003Feb 6 2003
     Re: eh...
58.
Feb 8, 2003Feb 8 2003
     Re: eh...
29.
Feb 6, 2003Feb 6 2003
    Re: eh...
31.
Feb 6, 2003Feb 6 2003
     Re: eh...
30.
Feb 6, 2003Feb 6 2003
    Re: eh...
32.
Feb 6, 2003Feb 6 2003
33.
Feb 6, 2003Feb 6 2003
34.
Feb 6, 2003Feb 6 2003
  Nice.
35.
Feb 6, 2003Feb 6 2003
36.
Feb 6, 2003Feb 6 2003
37.
Feb 6, 2003Feb 6 2003
40.
Feb 6, 2003Feb 6 2003
 39.
Feb 6, 2003Feb 6 2003
  Re: No subject
42.
Feb 6, 2003Feb 6 2003
52.
Feb 7, 2003Feb 7 2003
53.
Feb 7, 2003Feb 7 2003
56.
Feb 8, 2003Feb 8 2003
57.
Feb 8, 2003Feb 8 2003
    Respect!
54.
Feb 7, 2003Feb 7 2003
38.
Feb 6, 2003Feb 6 2003
41.
Feb 6, 2003Feb 6 2003
43.
Feb 6, 2003Feb 6 2003
44.
Feb 7, 2003Feb 7 2003
45.
Feb 7, 2003Feb 7 2003
46.
Feb 7, 2003Feb 7 2003
50.
Feb 7, 2003Feb 7 2003
51.
Feb 7, 2003Feb 7 2003
    Geez...
47.
Feb 7, 2003Feb 7 2003
48.
Feb 7, 2003Feb 7 2003
49.
Feb 7, 2003Feb 7 2003
55.
Feb 7, 2003Feb 7 2003
59.
Feb 9, 2003Feb 9 2003
60.
Feb 9, 2003Feb 9 2003
61.
Feb 9, 2003Feb 9 2003
62.
Feb 10, 2003Feb 10 2003
63.
Feb 10, 2003Feb 10 2003
64.
Feb 11, 2003Feb 11 2003
65.
Feb 11, 2003Feb 11 2003
66.
Feb 11, 2003Feb 11 2003
67.
Feb 11, 2003Feb 11 2003
68.
Feb 12, 2003Feb 12 2003