Lucene search

K
cve[email protected]CVE-2011-3012
HistoryAug 09, 2011 - 8:55 p.m.

CVE-2011-3012

2011-08-0920:55:00
CWE-20
web.nvd.nist.gov
23
ioquake3
engine
remote attackers
arbitrary code
crafted
addon
nvd
cve-2011-3012

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.108 Low

EPSS

Percentile

95.1%

The ioQuake3 engine, as used in World of Padman 1.2 and earlier, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerous file extensions before writing to the quake3 directory, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file, a different vulnerability than CVE-2011-2764.

Affected configurations

NVD
Node
ioquake3ioquake3_engine
OR
tremuloustremulousMatch1.1.0
OR
urbanterroriourbanterrorMatch2007-12-20
OR
worldofpadmanworld_of_padmanRange1.2

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.108 Low

EPSS

Percentile

95.1%