Vulnerability Description
The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ioquake3 | Ioquake3 Engine | <= 1.36 |
| Openarena | Openarena | All versions |
| Smokin-Guns | Smokin\' Guns | All versions |
| Tremulous | Tremulous | All versions |
| Urbanterror | Iourbanterror | All versions |
| Worldofpadman | World Of Padman | All versions |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/fulldisclosure/2011-07/0338.htmlExploit
- http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063460.htm
- http://secunia.com/advisories/45539
- http://secunia.com/advisories/45540
- http://securityreason.com/securityalert/8324
- http://svn.icculus.org/quake3?view=rev&revision=2098Patch
- http://thilo.tjps.eu/download/patches/ioq3-svn-r2098.diffPatch
- http://www.securityfocus.com/archive/1/519051/100/0/threaded
- http://www.securityfocus.com/bid/48915
- https://bugzilla.redhat.com/show_bug.cgi?id=725951ExploitPatch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68870
- https://security.gentoo.org/glsa/201706-23
- http://archives.neohapsis.com/archives/fulldisclosure/2011-07/0338.htmlExploit
- http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063460.htm
- http://secunia.com/advisories/45539
FAQ
What is CVE-2011-2764?
CVE-2011-2764 is a vulnerability with a CVSS score of 10.0 (HIGH). The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not pro...
How severe is CVE-2011-2764?
CVE-2011-2764 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-2764?
Check the references section above for vendor advisories and patch information. Affected products include: Ioquake3 Ioquake3 Engine, Openarena Openarena, Smokin-Guns Smokin\' Guns, Tremulous Tremulous, Urbanterror Iourbanterror.