PT-2011-3108 · Openarena Team+2 · Openarena+2

Publicado

2011-08-04

·

Atualizado

2018-10-09

·

CVE-2011-1412

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ioQuake3 engine versions prior to 1.5.1.1 World of Padman versions 1.5.x prior to 1.5.1.1 OpenArena versions 0.8.x-15 and 0.8.x-16
Description The issue allows remote game servers to execute arbitrary commands via shell metacharacters in a long fs game variable. This is due to a problem in the sys/sys unix.c file of the ioQuake3 engine on Unix and Linux systems.
Recommendations For ioQuake3 engine versions prior to 1.5.1.1, update to version 1.5.1.1 or later to resolve the issue. For World of Padman versions 1.5.x prior to 1.5.1.1, update to version 1.5.1.1 or later to resolve the issue. For OpenArena versions 0.8.x-15 and 0.8.x-16, consider disabling the use of the fs game variable until a patch is available.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1412

Produtos afetados

Openarena
World Of Padman
Quake 3 Engine