CVE-2010-5077: Input Validation
server/svmain.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote attackers to cause a denial of service (network traffic amplification) via a spoofed (1) getstatus or (2) rcon request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-5077?
CVE-2010-5077 has a denial of service vulnerability that can lead to network traffic amplification, affecting the availability of the service.
How do I fix CVE-2010-5077?
To fix CVE-2010-5077, upgrade to versions of ioquake3, OpenArena, or Tremulous that are not affected by this vulnerability.
Which versions are affected by CVE-2010-5077?
Versions of ioquake3 prior to r1762 and certain versions of OpenArena and Tremulous are affected by CVE-2010-5077.
What products utilize the vulnerable code in CVE-2010-5077?
CVE-2010-5077 affects ioquake3, OpenArena, and Tremulous among other products.
Can CVE-2010-5077 be exploited remotely?
Yes, CVE-2010-5077 can be exploited remotely through spoofed requests, leading to denial of service.