|
Quake 3 Buffer Overflow Vulnerabilities
|
|
Secunia Advisory:
|
SA20946
|
|
|
Release Date:
|
2006-07-04
|
|
Last Update:
|
2006-07-11
|
|
Popularity:
|
10,925 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
DoS System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Partial Fix
|
|
| Software: | Quake3 Engine 1.x Soldier of Fortune II 1.x
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: RunningBon has reported two vulnerabilities in the Quake 3 Engine, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system.
1) A boundary error exist in the "CG_ServerCommand()" function when receiving long server commands. This can be exploited to cause a stack-based buffer overflow via overly long server commands sent from the server.
Successful exploitation may allow arbitrary code execution, but requires that the user is e.g. tricked into connecting to a malicious server.
Reportedly, this vulnerability only affects Soldier of Fortune II and older versions of the Quake3 engine.
2) A boundary error exists in the handling of CS_ITEMS sent from a server. This can be exploited to cause a stack-based buffer overflow by sending overly long values to the client.
Successful exploitation may allow arbitrary code execution, but requires that the user is e.g. tricked into connecting to a malicious server.
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|