CVE-2011-1412: Input Validation
sys/sysunix.c in the ioQuake3 engine on Unix and Linux, as used in World of Padman 1.5.x before 1.5.1.1 and OpenArena 0.8.x-15 and 0.8.x-16, allows remote game servers to execute arbitrary commands via shell metacharacters in a long fsgame variable.
Other sources
Two security vulnerabilities in the ioquake3 engine may affect your quake3 and/or openarena packages. I will comment with more details when I have confirmed that this bug is not public.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1412?
CVE-2011-1412 has a high severity rating due to its potential to allow remote command execution.
How do I fix CVE-2011-1412?
To fix CVE-2011-1412, update to the patched versions of ioQuake3 engine or World of Padman after version 1.5.1.1 or OpenArena version 0.8.x-16.
Which software is affected by CVE-2011-1412?
CVE-2011-1412 affects ioQuake3 engine in versions before 1.5.1.1, OpenArena versions 0.8.x-15, and 0.8.x-16, and World of Padman version 1.5.
What is the exploit method for CVE-2011-1412?
The exploit method for CVE-2011-1412 involves using shell metacharacters in a lengthy fs_game variable to execute arbitrary commands.
Are Linux distributions vulnerable due to CVE-2011-1412?
The Linux kernel itself is not vulnerable to CVE-2011-1412, but the applications running on it may be affected.