CVE-2011-2764
Summary
| CVE | CVE-2011-2764 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-08-04 02:45:32 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ioquake3 | Ioquake3 Engine | 1.36 | rc1 | All | All |
| Application | Ioquake3 | Ioquake3 Engine | All | All | All | All |
| Application | Openarena | Openarena | All | All | All | All |
| Application | Smokin-guns | Smokin Guns | All | All | All | All |
| Application | Tremulous | Tremulous | All | All | All | All |
| Application | Urbanterror | Iourbanterror | All | All | All | All |
| Application | Worldofpadman | World Of Padman | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 14 Update: quake3-1.36-11.svn2102.fc14 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| ioQuake3 Engine Multiple Remote Code Execution Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Fedora update for openarena - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Fedora update for quake3 - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| ioQuake3 Remote shell injection - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| NEOHAPSIS - Peace of Mind Through Integrity and Insight | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Exploit |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | thilo.tjps.eu | Patch |
| Urban Terror: Multiple vulnerabilities (GLSA 201706-23) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| [quake3] Revision 2098 | af854a3a-2127-422b-91ae-364da2661108 | svn.icculus.org | Patch |
| 725951 – (CVE-2011-1412, CVE-2011-2764, CVE-2011-3012) CVE-2011-1412 CVE-2011-2764 CVE-2011-3012 quake3: arbitrary code execution vulnerabilites in ioquake3 | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Exploit, Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710537 Gentoo Linux Urban Terror Multiple Vulnerabilities (GLSA 201706-23)