Exploitation Summary
EIP tracks 1 public exploit for CVE-2004-1500. PoCs published by Luigi Auriemma.
AI-analyzed exploit summary This exploit demonstrates a format string vulnerability in the Lithtech game engine (F.E.A.R. <= 1.08) via malformed UDP packets sent to port 27888. It leverages incorrect usage of printf-type functions to trigger a denial-of-service or potential remote code execution.
Description
Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.
Exploits (1)
This exploit demonstrates a format string vulnerability in the Lithtech game engine (F.E.A.R. <= 1.08) via malformed UDP packets sent to port 27888. It leverages incorrect usage of printf-type functions to trigger a denial-of-service or potential remote code execution.