CVE-2017-6903: High severity ioquake3 ioquake3 vulnerability
In ioquake3 before 2017-03-14, the auto-downloading feature has insufficient content restrictions. This also affects Quake III Arena, OpenArena, OpenJK, iortcw, and other id Tech 3 (aka Quake 3 engine) forks. A malicious auto-downloaded file can trigger loading of crafted auto-downloaded files as native code DLLs. A malicious auto-downloaded file can contain configuration defaults that override the user's. Executable bytecode in a malicious auto-downloaded file can set configuration variables to values that will result in unwanted native code DLLs being loaded, resulting in sandbox escape.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ioquake3to a version that resolves this vulnerability.Fixed in 1.36+u20201117.d1b7ab6~dfsg-1Fixed in 1.36+u20221123.70d07d9+dfsg-1Fixed in 1.36+u20240714.15f5fe7+dfsg-1 - Upgrade
Upgrade
debian/iortcwto a version that resolves this vulnerability.Fixed in 1.51.c+dfsg1-3Fixed in 1.51.c+dfsg1-4Fixed in 1.51.c+dfsg1-7 - Compensating control
Disable or restrict the id Tech 3 engine auto-downloading feature on ioquake3 (and affected forks: Quake III Arena, OpenArena, OpenJK, iortcw, and other id Tech 3 forks) to prevent malicious auto-downloaded configuration/scripts from overriding user settings and from triggering loading of crafted native-code DLLs.
- Compensating control
Apply stricter content restrictions for auto-downloaded files in ioquake3 for all versions before 2017-03-14 to prevent executable bytecode from setting configuration variables that cause unwanted native-code DLLs to be loaded and lead to sandbox escape.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6903?
CVE-2017-6903 is classified as a high severity vulnerability due to the potential for remote code execution via malicious auto-downloaded files.
How do I fix CVE-2017-6903?
To remediate CVE-2017-6903, update ioquake3 or iortcw to their fixed versions as specified by Debian security advisories.
What versions of ioquake3 are affected by CVE-2017-6903?
Versions of ioquake3 prior to 2017-02-27 are affected by CVE-2017-6903.
What types of software are impacted by CVE-2017-6903?
CVE-2017-6903 affects ioquake3, Quake III Arena, OpenArena, OpenJK, iortcw, and other id Tech 3 forks.
What kind of exploit could occur due to CVE-2017-6903?
Exploiting CVE-2017-6903 could allow a malicious actor to load and execute crafted files automatically without user consent.