CVE-2011-2764

NameCVE-2011-2764
DescriptionThe FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs660836

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ioquake3 (PTS)buster1.36+u20181222.e5da13f~dfsg-2fixed
bullseye1.36+u20201117.d1b7ab6~dfsg-1fixed
bookworm1.36+u20221123.70d07d9+dfsg-1fixed
sid, trixie1.36+u20240217.7d711f8+dfsg-1fixed
openarena (PTS)buster0.8.8+dfsg-2fixed
bullseye0.8.8+dfsg-5fixed
bookworm0.8.8+dfsg-6fixed
sid, trixie0.8.8+dfsg-7fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ioquake3source(unstable)1.36+svn1946-4
openarenasourcesqueeze0.8.5-5+squeeze1
openarenasource(unstable)0.8.5-5+exp1
tremuloussourcesqueeze1.1.0-7~squeeze1
tremuloussource(unstable)1.1.0-6660836

Notes

Current openarena packages use the share ioquake3 engine

Search for package or bug name: Reporting problems