CVE-2010-5077
Summary
| CVE | CVE-2010-5077 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-10-27 20:55:09 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote attackers to cause a denial of service (network traffic amplification) via a spoofed (1) getstatus or (2) rcon request. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:L/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| DRDoS - Urban Terror Forums | af854a3a-2127-422b-91ae-364da2661108 | www.urbanterror.info | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Debian -- Security Information -- DSA-2442-1 openarena | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| oss-security - Re: CVE-2010 Request: quake3 / openarena-server: DDoS by processing 'getstatus' and 'rcon' packets | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| My server is getting bot striked... | af854a3a-2127-422b-91ae-364da2661108 | openarena.ws | |
| permalink.gmane.org | 522: Connection timed out | af854a3a-2127-422b-91ae-364da2661108 | permalink.gmane.org | |
| ioquake.org forums • View topic - DDOS attack on ioquake3 servers | af854a3a-2127-422b-91ae-364da2661108 | www.ioquake.org | |
| #665656 - openarena-server: [CVE-2010-5077] traffic amplification via getstatus requests - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.