A recently published report originally spotted by
3DGPU on the BugTraq listing has news
of a vulnerability in Epic's Unreal engine that leaves machines open to participate in
DDoS attacks and the popular spoofed UDP packets fun. The person who discovered the
exploit privately notified Epic nearly 3 months ago which was a sweetheart thing of him to
do. However Epic dropped the ball for a bit too long. Bluesnews
has a
quote and a
fix list
from Mark Rein on the subject:
I won't sugar coat this. We fucked up on this. Yes this
is real and yes this was brought to our attention and yes we should have fixed it by now.
We are working on fixing this now and we will have this fixed in an upcoming patch before
too long
This exploit works on all Unreal/Unreal2/UT2003 engine based titles, and once Epic has the fix they
will make it available to all licensees.