PT-2011-3108 · Openarena Team+2 · Openarena+2
Publicado
2011-08-04
·
Atualizado
2018-10-09
·
CVE-2011-1412
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ioQuake3 engine versions prior to 1.5.1.1
World of Padman versions 1.5.x prior to 1.5.1.1
OpenArena versions 0.8.x-15 and 0.8.x-16
Description
The issue allows remote game servers to execute arbitrary commands via shell metacharacters in a long
fs game variable. This is due to a problem in the sys/sys unix.c file of the ioQuake3 engine on Unix and Linux systems.Recommendations
For ioQuake3 engine versions prior to 1.5.1.1, update to version 1.5.1.1 or later to resolve the issue.
For World of Padman versions 1.5.x prior to 1.5.1.1, update to version 1.5.1.1 or later to resolve the issue.
For OpenArena versions 0.8.x-15 and 0.8.x-16, consider disabling the use of the
fs game variable until a patch is available.Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openarena
World Of Padman
Quake 3 Engine