CVE Database
/

CVE-2011-2764

Back to search

CVE-2011-2764

Published: Aug 4, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file.

VendorProductVersions

n/a

n/a

affected
n/a

References

45540
third-party-advisory
x_refsource_SECUNIA
45539
third-party-advisory
x_refsource_SECUNIA
48915
vdb-entry
x_refsource_BID
8324
third-party-advisory
x_refsource_SREASON
GLSA-201706-23
vendor-advisory
x_refsource_GENTOO
FEDORA-2011-9898
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now