The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36...
Vulnerability Description
The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-2764
Credits & Attribution
No credits recorded in the NVD database.
References
- http://archives.neohapsis.com/archives/fulldisclosure/2011-07/0338.html
- http://svn.icculus.org/quake3?view=rev&revision=2098
- http://secunia.com/advisories/45540
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68870
- http://secunia.com/advisories/45539
- https://bugzilla.redhat.com/show_bug.cgi?id=725951
- http://thilo.tjps.eu/download/patches/ioq3-svn-r2098.diff
- http://www.securityfocus.com/bid/48915
- http://www.securityfocus.com/archive/1/519051/100/0/threaded
- http://securityreason.com/securityalert/8324
- https://security.gentoo.org/glsa/201706-23
- http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063460.html
More from ioquake3
View All →Affected Vendor
ioquake3
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.