CVE-2011-2764: Input Validation
The FSCheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2764?
CVE-2011-2764 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2011-2764?
To fix CVE-2011-2764, update to a patched version of the ioQuake3 engine or related software that addresses the vulnerability.
Which software is affected by CVE-2011-2764?
CVE-2011-2764 affects several software programs including ioQuake3, World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror.
What type of vulnerability is CVE-2011-2764?
CVE-2011-2764 is a vulnerability that allows remote attackers to execute arbitrary code due to improper filename checking.
Can CVE-2011-2764 be exploited remotely?
Yes, CVE-2011-2764 can be exploited remotely as it allows for arbitrary code execution on affected systems.