HIGH · 10.0

CVE-2011-3012

The ioQuake3 engine, as used in World of Padman 1.2 and earlier, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerous file extensions before writing to the quake3 directory, whi...

Vulnerability Description

The ioQuake3 engine, as used in World of Padman 1.2 and earlier, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerous file extensions before writing to the quake3 directory, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file, a different vulnerability than CVE-2011-2764.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Ioquake3Ioquake3 EngineAll versions
TremulousTremulous1.1.0
UrbanterrorIourbanterror2007-12-20
WorldofpadmanWorld Of Padman<= 1.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-3012?

CVE-2011-3012 is a vulnerability with a CVSS score of 10.0 (HIGH). The ioQuake3 engine, as used in World of Padman 1.2 and earlier, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerous file extensions before writing to the quake3 directory, whi...

How severe is CVE-2011-3012?

CVE-2011-3012 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-3012?

Check the references section above for vendor advisories and patch information. Affected products include: Ioquake3 Ioquake3 Engine, Tremulous Tremulous, Urbanterror Iourbanterror, Worldofpadman World Of Padman.