CVE Database
/

CVE-2011-3012

Back to search

CVE-2011-3012

Published: Aug 9, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

The ioQuake3 engine, as used in World of Padman 1.2 and earlier, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerous file extensions before writing to the quake3 directory, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file, a different vulnerability than CVE-2011-2764.

VendorProductVersions

n/a

n/a

affected
n/a

References

48915
vdb-entry
x_refsource_BID
8324
third-party-advisory
x_refsource_SREASON
GLSA-201706-23
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now