René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

159 lines
5.1 KiB
JSON

{
"id": "CVE-2011-2764",
"sourceIdentifier": "cve@mitre.org",
"published": "2011-08-04T02:45:32.343",
"lastModified": "2018-10-09T19:33:02.917",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file."
},
{
"lang": "es",
"value": "La funci\u00f3n FS_CheckFilenameIsNotExecutable de qcommon/files.c en el motor de ioQuake3 1.36 y versiones anteriores, tal como se usa en \"World of Padman\", \"Smokin' Guns\", OpenArena, Tremulous y ioUrbanTerror, no detecta extensiones de archivo peligrosas, lo que permite a atacantes remotos ejecutar c\u00f3digo arbitrario a trav\u00e9s de un complemento de terceras partes modificado que crea un archivo DLL troyanizado."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 10.0
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ioquake3:ioquake3_engine:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.36",
"matchCriteriaId": "0A70EB58-3D3F-4A80-AD7C-0592C3BD3D3C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ioquake3:ioquake3_engine:1.36:rc1:*:*:*:*:*:*",
"matchCriteriaId": "631580B6-FB90-44D0-A960-DE418F684FF2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openarena:openarena:*:*:*:*:*:*:*:*",
"matchCriteriaId": "C66CEED6-0C18-4A8C-8369-2C8E23434587"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:smokin-guns:smokin\\'_guns:*:*:*:*:*:*:*:*",
"matchCriteriaId": "00EBAD21-CC29-4EF3-BE6D-334734D175FE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:tremulous:tremulous:*:*:*:*:*:*:*:*",
"matchCriteriaId": "63624600-4577-4D6E-A733-1668CFD7732C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:urbanterror:iourbanterror:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F9CA0A90-BF68-4294-86E5-4CF170709C08"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:worldofpadman:world_of_padman:*:*:*:*:*:*:*:*",
"matchCriteriaId": "C7D65EC1-0FB2-4628-B877-EE1B00A26B56"
}
]
}
]
}
],
"references": [
{
"url": "http://archives.neohapsis.com/archives/fulldisclosure/2011-07/0338.html",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063460.html",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/8324",
"source": "cve@mitre.org"
},
{
"url": "http://svn.icculus.org/quake3?view=rev&revision=2098",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://thilo.tjps.eu/download/patches/ioq3-svn-r2098.diff",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www.securityfocus.com/archive/1/519051/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/48915",
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=725951",
"source": "cve@mitre.org",
"tags": [
"Exploit",
"Patch"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/68870",
"source": "cve@mitre.org"
},
{
"url": "https://security.gentoo.org/glsa/201706-23",
"source": "cve@mitre.org"
}
]
}