CVE-2011-3012: Input Validation
The ioQuake3 engine, as used in World of Padman 1.2 and earlier, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerous file extensions before writing to the quake3 directory, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file, a different vulnerability than CVE-2011-2764.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3012?
CVE-2011-3012 is classified as a high-severity vulnerability due to its ability to allow remote code execution.
How do I fix CVE-2011-3012?
To fix CVE-2011-3012, ensure you are using an updated version of the affected software that includes a patch for this vulnerability.
Which software is affected by CVE-2011-3012?
CVE-2011-3012 affects ioQuake3, World of Padman versions up to 1.2, Tremulous version 1.1.0, and Urban Terror from 2007-12-20.
Can CVE-2011-3012 be exploited remotely?
Yes, CVE-2011-3012 can be exploited remotely by an attacker through a crafted third-party addon.
What is the impact of exploiting CVE-2011-3012?
Exploiting CVE-2011-3012 can lead to arbitrary code execution on the affected systems.