CVE-2004-2361
Description
Digital Reality game engine, as used in Haegemonia 1.0 through 1.0.7 and Desert Rats vs. Afrika Korps 1.0, allows remote attackers to cause a denial of service (crash) via a chat message with a large message size, which triggers an out-of-bounds read.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Remote attackers can crash Haegemonia (<=1.07) and Desert Rats vs. Afrika Korps (1.0) servers by sending a crafted chat message with an oversized length field.
Vulnerability
The Digital Reality game engine used in Haegemonia versions 1.0 through 1.0.7 and Desert Rats vs. Afrika Korps version 1.0 contains an out-of-bounds read vulnerability. The bug is triggered when a remote attacker sends a chat message packet where the 32-bit field specifying the message length is set to an excessively large value. This causes the server to read beyond the allocated memory buffer, resulting in a crash [1][2].
Exploitation
An attacker needs only network access to the game server. For servers using the Gamespy Internet matchmaking system, the vulnerability is exploitable only when the server is in the final multiplayer lobby (the screen reached after launching the server without Gamespy support), not in the earlier chat room screen [1]. The attacker sends a single crafted packet containing a chat message with an oversized length value. No authentication or user interaction is required [1][2].
Impact
A successful exploit causes the server to attempt to read from unallocated memory, leading to a denial of service (crash) of the game server process. The attacker does not gain any code execution or data access; the impact is purely availability loss for the multiplayer session [1][2].
Mitigation
No official fix was ever released by the developer; the vendor did not respond to the reporter's disclosure emails [1][2]. As of the publication date (2004-12-31), users must rely on network-level filtering or restrict access to trusted players to prevent exploitation. The games are now legacy titles and are not listed on the CISA KEV catalog [1][2].
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 1.0 - 1.0.7
- Range: 1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- aluigi.altervista.org/adv/hgmcrash-adv.txtnvdExploitVendor Advisory
- www.securityfocus.com/bid/9736nvdExploit
- marc.infonvd
- www.osvdb.org/10631nvd
- www.osvdb.org/10632nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/15307nvd
News mentions
0No linked articles in our index yet.