VYPR
Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026

CVE-2004-1492

CVE-2004-1492

Description

Master of Orion III 1.2.5 and earlier crashes when receiving a crafted packet with an oversized size field, causing a failed memory allocation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Master of Orion III 1.2.5 and earlier crashes when receiving a crafted packet with an oversized size field, causing a failed memory allocation.

Vulnerability

Master of Orion III versions 1.2.5 and earlier contain a denial-of-service vulnerability in the network protocol handling. Each data packet exchanged between clients and the server includes a 32-bit size field that the game uses to allocate memory. If an attacker sends a packet with an excessively large size value, the memory allocation fails and the game exits immediately [1].

Exploitation

An unauthenticated remote attacker can send a crafted data packet to a Master of Orion III server or client. The packet must contain a size specifier larger than the game can allocate. No user interaction is required; the game processes the packet and attempts the allocation, causing a crash [1].

Impact

Successful exploitation results in a denial of service: the game process terminates. No data is corrupted or disclosed, and no code execution is achieved. The crash affects both server and client instances [1].

Mitigation

No official patch has been released for this vulnerability. Master of Orion III is a legacy game and is no longer supported. As a workaround, restrict network access to the game to trusted hosts or play offline. The vulnerability is listed in the CVE database but not on the CISA KEV [1].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:a:quicksilver:master_of_orion_iii:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:quicksilver:master_of_orion_iii:*:*:*:*:*:*:*:*range: <=1.2.5
    • (no CPE)range: <=1.2.5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.