vendor:
UFO: Alien Invasion
by:
Jason Geffner
7.5
CVSS
HIGH
Remote Arbitrary Code Execution
CWE
Product Name: UFO: Alien Invasion
Affected Version From: UFO: Alien Invasion 2.2.1
Affected Version To: UFO: Alien Invasion 2.3
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: Linux, Microsoft Windows, and Mac OS X
2010
Remote Arbitrary Code Execution Vulnerability in UFO: Alien Invasion
This paper discusses how an unprivileged remote attacker can execute arbitrary code on networked players' computers. The IRC client component of UFO: Alien Invasion 2.2.1 contains multiple security vulnerabilities that allow a malicious IRC server to remotely execute arbitrary code on the client's computer.
Mitigation:
A stable build of UFO: Alien Invasion 2.3 was released to fix the vulnerability.