CVE-2011-2764
EPSS 5.8%
Description
The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file.
How to fix CVE-2011-2764
To remediate CVE-2011-2764, upgrade the affected package to a fixed version below.
- Debian/ioquake3—upgrade to 1.36+svn1946-4 or later
- Debian/openarena—upgrade to 0.8.5-5+exp1 or later
Is CVE-2011-2764 being exploited?
Moderate — EPSS is 5.8%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 1.36+svn1946-4
- from 0, < 0.8.5-5+exp1