PT-2011-3108 · Openarena Team+2 · Openarena+2

Published

2011-08-04

·

Updated

2018-10-09

·

CVE-2011-1412

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ioQuake3 engine versions prior to 1.5.1.1 World of Padman versions 1.5.x prior to 1.5.1.1 OpenArena versions 0.8.x-15 and 0.8.x-16
Description The issue allows remote game servers to execute arbitrary commands via shell metacharacters in a long fs game variable. This is due to a problem in the sys/sys unix.c file of the ioQuake3 engine on Unix and Linux systems.
Recommendations For ioQuake3 engine versions prior to 1.5.1.1, update to version 1.5.1.1 or later to resolve the issue. For World of Padman versions 1.5.x prior to 1.5.1.1, update to version 1.5.1.1 or later to resolve the issue. For OpenArena versions 0.8.x-15 and 0.8.x-16, consider disabling the use of the fs game variable until a patch is available.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1412

Affected Products

Openarena
World Of Padman
Quake 3 Engine