VYPR
Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026

CVE-2004-2361

CVE-2004-2361

Description

Digital Reality game engine, as used in Haegemonia 1.0 through 1.0.7 and Desert Rats vs. Afrika Korps 1.0, allows remote attackers to cause a denial of service (crash) via a chat message with a large message size, which triggers an out-of-bounds read.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Remote attackers can crash Haegemonia (<=1.07) and Desert Rats vs. Afrika Korps (1.0) servers by sending a crafted chat message with an oversized length field.

Vulnerability

The Digital Reality game engine used in Haegemonia versions 1.0 through 1.0.7 and Desert Rats vs. Afrika Korps version 1.0 contains an out-of-bounds read vulnerability. The bug is triggered when a remote attacker sends a chat message packet where the 32-bit field specifying the message length is set to an excessively large value. This causes the server to read beyond the allocated memory buffer, resulting in a crash [1][2].

Exploitation

An attacker needs only network access to the game server. For servers using the Gamespy Internet matchmaking system, the vulnerability is exploitable only when the server is in the final multiplayer lobby (the screen reached after launching the server without Gamespy support), not in the earlier chat room screen [1]. The attacker sends a single crafted packet containing a chat message with an oversized length value. No authentication or user interaction is required [1][2].

Impact

A successful exploit causes the server to attempt to read from unallocated memory, leading to a denial of service (crash) of the game server process. The attacker does not gain any code execution or data access; the impact is purely availability loss for the multiplayer session [1][2].

Mitigation

No official fix was ever released by the developer; the vendor did not respond to the reporter's disclosure emails [1][2]. As of the publication date (2004-12-31), users must rely on network-level filtering or restrict access to trusted players to prevent exploitation. The games are now legacy titles and are not listed on the CISA KEV catalog [1][2].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.