Unrated severityNVD Advisory· Published Oct 6, 2007· Updated Apr 23, 2026
CVE-2007-5248
CVE-2007-5248
Description
Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in (1) a PB_Y packet to the YPG server or (2) a PB_U packet to UCON. NOTE: this issue might be in Punkbuster itself, but there are insufficient details to be certain.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- aluigi.altervista.org/adv/d3engfspb-adv.txtnvdExploit
- aluigi.org/poc/d3engfspb.zipnvdExploit
- secunia.com/advisories/27002nvdVendor Advisory
- secunia.com/advisories/27023nvdVendor Advisory
- secunia.com/advisories/27036nvdVendor Advisory
- securityreason.com/securityalert/3196nvd
- www.securityfocus.com/archive/1/481229/100/0/threadednvd
- www.securityfocus.com/bid/25893nvd
- www.vupen.com/english/advisories/2007/3333nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/36899nvd
News mentions
0No linked articles in our index yet.