{ "id": "CVE-2021-32238", "sourceIdentifier": "cve@mitre.org", "published": "2021-05-18T15:15:08.070", "lastModified": "2021-05-25T15:26:33.947", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "Epic Games / Psyonix Rocket League <=1.95 is affected by Buffer Overflow. Stack-based buffer overflow occurs when Rocket League handles UPK object files that can result in code execution and denial of service scenario." }, { "lang": "es", "value": "Epic Games/Psyonix Rocket League versiones anteriores a 1.95 incluy\u00e9ndola, est\u00e1 afectado por un Desbordamiento del B\u00fafer. El desbordamiento del b\u00fafer en la regi\u00f3n stack de la memoria ocurre cuando Rocket League maneja archivos de objetos UPK que pueden resultar en una ejecuci\u00f3n de c\u00f3digo y en un escenario de denegaci\u00f3n de servicio" } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH" }, "exploitabilityScore": 1.8, "impactScore": 5.9 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "availabilityImpact": "COMPLETE", "baseScore": 9.3 }, "baseSeverity": "HIGH", "exploitabilityScore": 8.6, "impactScore": 10.0, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-787" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:psyonix:rocket_league:*:*:*:*:*:*:*:*", "versionEndIncluding": "1.95", "matchCriteriaId": "04D4FC05-D420-4EBA-8FAE-A2376D3D619D" } ] } ] } ], "references": [ { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/201129", "source": "cve@mitre.org", "tags": [ "VDB Entry", "Vendor Advisory" ] }, { "url": "https://www.zeroscience.mk/en/vulnerabilities/", "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ] }, { "url": "https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5651.php", "source": "cve@mitre.org", "tags": [ "Exploit", "Third Party Advisory" ] } ] }