{"api_version":"1","generated_at":"2026-07-23T08:10:13+00:00","cve":"CVE-2011-2764","urls":{"html":"https://cve.report/CVE-2011-2764","api":"https://cve.report/api/cve/CVE-2011-2764.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-2764","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-2764"},"summary":{"title":"CVE-2011-2764","description":"The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file.","state":"PUBLISHED","assigner":"mitre","published_at":"2011-08-04 02:45:32","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063460.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063460.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[SECURITY] Fedora 14 Update: quake3-1.36-11.svn2102.fc14","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/48915","name":"http://www.securityfocus.com/bid/48915","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ioQuake3 Engine Multiple Remote Code Execution Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/45539","name":"http://secunia.com/advisories/45539","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Fedora update for openarena - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/45540","name":"http://secunia.com/advisories/45540","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Fedora update for quake3 - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/8324","name":"http://securityreason.com/securityalert/8324","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ioQuake3 Remote shell injection - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/519051/100/0/threaded","name":"http://www.securityfocus.com/archive/1/519051/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/fulldisclosure/2011-07/0338.html","name":"http://archives.neohapsis.com/archives/fulldisclosure/2011-07/0338.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"NEOHAPSIS - Peace of Mind Through Integrity and Insight","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/68870","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/68870","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://thilo.tjps.eu/download/patches/ioq3-svn-r2098.diff","name":"http://thilo.tjps.eu/download/patches/ioq3-svn-r2098.diff","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"404 Not Found","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://security.gentoo.org/glsa/201706-23","name":"https://security.gentoo.org/glsa/201706-23","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Urban Terror: Multiple vulnerabilities (GLSA 201706-23) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://svn.icculus.org/quake3?view=rev&revision=2098","name":"http://svn.icculus.org/quake3?view=rev&revision=2098","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"[quake3] Revision 2098","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=725951","name":"https://bugzilla.redhat.com/show_bug.cgi?id=725951","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch"],"title":"725951 – (CVE-2011-1412, CVE-2011-2764, CVE-2011-3012) CVE-2011-1412 CVE-2011-2764 CVE-2011-3012 quake3: arbitrary code execution vulnerabilites in ioquake3","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-2764","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-2764","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"2764","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ioquake3","cpe5":"ioquake3_engine","cpe6":"1.36","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2764","vulnerable":"1","versionEndIncluding":"1.36","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ioquake3","cpe5":"ioquake3_engine","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2764","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openarena","cpe5":"openarena","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2764","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"smokin-guns","cpe5":"smokin\\'_guns","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2764","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tremulous","cpe5":"tremulous","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2764","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"urbanterror","cpe5":"iourbanterror","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2764","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"worldofpadman","cpe5":"world_of_padman","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2011-2764","qid":"710537","title":"Gentoo Linux Urban Terror Multiple Vulnerabilities (GLSA 201706-23)"}]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T23:15:30.694Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20110728 Two security issues fixed in ioQuake3 engine","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2011-07/0338.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://svn.icculus.org/quake3?view=rev&revision=2098"},{"name":"45540","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/45540"},{"name":"ioquake-gamecode-code-execution(68870)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/68870"},{"name":"45539","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/45539"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=725951"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://thilo.tjps.eu/download/patches/ioq3-svn-r2098.diff"},{"name":"48915","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/48915"},{"name":"20110728 Two security issues fixed in ioQuake3 engine","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/519051/100/0/threaded"},{"name":"8324","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/8324"},{"name":"GLSA-201706-23","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"https://security.gentoo.org/glsa/201706-23"},{"name":"FEDORA-2011-9898","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063460.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-07-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-09T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20110728 Two security issues fixed in ioQuake3 engine","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2011-07/0338.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://svn.icculus.org/quake3?view=rev&revision=2098"},{"name":"45540","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/45540"},{"name":"ioquake-gamecode-code-execution(68870)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/68870"},{"name":"45539","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/45539"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=725951"},{"tags":["x_refsource_CONFIRM"],"url":"http://thilo.tjps.eu/download/patches/ioq3-svn-r2098.diff"},{"name":"48915","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/48915"},{"name":"20110728 Two security issues fixed in ioQuake3 engine","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/519051/100/0/threaded"},{"name":"8324","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/8324"},{"name":"GLSA-201706-23","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"https://security.gentoo.org/glsa/201706-23"},{"name":"FEDORA-2011-9898","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063460.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2011-2764","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20110728 Two security issues fixed in ioQuake3 engine","refsource":"FULLDISC","url":"http://archives.neohapsis.com/archives/fulldisclosure/2011-07/0338.html"},{"name":"http://svn.icculus.org/quake3?view=rev&revision=2098","refsource":"CONFIRM","url":"http://svn.icculus.org/quake3?view=rev&revision=2098"},{"name":"45540","refsource":"SECUNIA","url":"http://secunia.com/advisories/45540"},{"name":"ioquake-gamecode-code-execution(68870)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/68870"},{"name":"45539","refsource":"SECUNIA","url":"http://secunia.com/advisories/45539"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=725951","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=725951"},{"name":"http://thilo.tjps.eu/download/patches/ioq3-svn-r2098.diff","refsource":"CONFIRM","url":"http://thilo.tjps.eu/download/patches/ioq3-svn-r2098.diff"},{"name":"48915","refsource":"BID","url":"http://www.securityfocus.com/bid/48915"},{"name":"20110728 Two security issues fixed in ioQuake3 engine","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/519051/100/0/threaded"},{"name":"8324","refsource":"SREASON","url":"http://securityreason.com/securityalert/8324"},{"name":"GLSA-201706-23","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201706-23"},{"name":"FEDORA-2011-9898","refsource":"FEDORA","url":"http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063460.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2011-2764","datePublished":"2011-08-04T01:00:00.000Z","dateReserved":"2011-07-19T00:00:00.000Z","dateUpdated":"2024-08-06T23:15:30.694Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-08-04 02:45:32","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ioquake3:ioquake3_engine:*:*:*:*:*:*:*:*","versionEndIncluding":"1.36","matchCriteriaId":"0A70EB58-3D3F-4A80-AD7C-0592C3BD3D3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:ioquake3:ioquake3_engine:1.36:rc1:*:*:*:*:*:*","matchCriteriaId":"631580B6-FB90-44D0-A960-DE418F684FF2"},{"vulnerable":true,"criteria":"cpe:2.3:a:openarena:openarena:*:*:*:*:*:*:*:*","matchCriteriaId":"C66CEED6-0C18-4A8C-8369-2C8E23434587"},{"vulnerable":true,"criteria":"cpe:2.3:a:smokin-guns:smokin\\'_guns:*:*:*:*:*:*:*:*","matchCriteriaId":"00EBAD21-CC29-4EF3-BE6D-334734D175FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:tremulous:tremulous:*:*:*:*:*:*:*:*","matchCriteriaId":"63624600-4577-4D6E-A733-1668CFD7732C"},{"vulnerable":true,"criteria":"cpe:2.3:a:urbanterror:iourbanterror:*:*:*:*:*:*:*:*","matchCriteriaId":"F9CA0A90-BF68-4294-86E5-4CF170709C08"},{"vulnerable":true,"criteria":"cpe:2.3:a:worldofpadman:world_of_padman:*:*:*:*:*:*:*:*","matchCriteriaId":"C7D65EC1-0FB2-4628-B877-EE1B00A26B56"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"2764","Ordinal":"1","Title":"CVE-2011-2764","CVE":"CVE-2011-2764","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"2764","Ordinal":"1","NoteData":"The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file.","Type":"Description","Title":"CVE-2011-2764"},{"CveYear":"2011","CveId":"2764","Ordinal":"2","NoteData":"2011-08-03","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"2764","Ordinal":"3","NoteData":"2018-10-09","Type":"Other","Title":"Modified"}]}}}