First published: Thu Aug 04 2011(Updated: )
The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Urban Terror | ||
ioQuake3 | =1.36-rc1 | |
Tremulous | ||
ioQuake3 | <=1.36 | |
Smokin' Guns | ||
World of Padman | ||
npm |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2764 has a high severity rating due to its potential for remote code execution.
To fix CVE-2011-2764, update to a patched version of the ioQuake3 engine or related software that addresses the vulnerability.
CVE-2011-2764 affects several software programs including ioQuake3, World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror.
CVE-2011-2764 is a vulnerability that allows remote attackers to execute arbitrary code due to improper filename checking.
Yes, CVE-2011-2764 can be exploited remotely as it allows for arbitrary code execution on affected systems.