~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2011-2764

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2011-2764
2
 
PublicDate: 2011-08-03
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2764
5
 
 https://bugzilla.redhat.com/show_bug.cgi?id=725951
6
 
 http://archives.neohapsis.com/archives/fulldisclosure/2011-07/0338.html
7
 
Description:
8
 
 The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the
9
 
 ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns,
10
 
 OpenArena, Tremulous, and ioUrbanTerror, does not properly determine
11
 
 dangerous file extensions, which allows remote attackers to execute
12
 
 arbitrary code via a crafted third-party addon that creates a Trojan horse
13
 
 DLL file.
14
 
Ubuntu-Description:
15
 
Notes:
16
 
Bugs:
17
 
Priority: medium
18
 
Discovered-by:
19
 
Assigned-to:
20
 
 
21
 
Patches_openarena:
22
 
upstream_openarena: needs-triage
23
 
hardy_openarena: ignored (reached end-of-life)
24
 
lucid_openarena: ignored (reached end-of-life)
25
 
maverick_openarena: ignored (reached end-of-life)
26
 
natty_openarena: ignored (reached end-of-life)
27
 
oneiric_openarena: ignored (reached end-of-life)
28
 
precise_openarena: ignored (reached end-of-life)
29
 
precise/esm_openarena: DNE (precise was needed)
30
 
quantal_openarena: ignored (reached end-of-life)
31
 
raring_openarena: ignored (reached end-of-life)
32
 
saucy_openarena: ignored (reached end-of-life)
33
 
trusty_openarena: needed
34
 
utopic_openarena: ignored (reached end-of-life)
35
 
vivid_openarena: ignored (reached end-of-life)
36
 
vivid/stable-phone-overlay_openarena: DNE
37
 
vivid/ubuntu-core_openarena: DNE
38
 
wily_openarena: ignored (reached end-of-life)
39
 
xenial_openarena: needed
40
 
yakkety_openarena: ignored (reached end-of-life)
41
 
zesty_openarena: ignored (reached end-of-life)
42
 
artful_openarena: needed
43
 
bionic_openarena: needed
44
 
devel_openarena: needed
45
 
 
46
 
Patches_ioquake3:
47
 
 upstream: http://svn.icculus.org/quake3?view=rev&revision=2098
48
 
upstream_ioquake3: needs-triage
49
 
hardy_ioquake3: DNE
50
 
lucid_ioquake3: DNE
51
 
maverick_ioquake3: DNE
52
 
natty_ioquake3: ignored (reached end-of-life)
53
 
oneiric_ioquake3: ignored (reached end-of-life)
54
 
precise_ioquake3: not-affected (1.36+svn2202-1)
55
 
precise/esm_ioquake3: DNE (precise was not-affected [1.36+svn2202-1])
56
 
quantal_ioquake3: ignored (reached end-of-life)
57
 
raring_ioquake3: ignored (reached end-of-life)
58
 
saucy_ioquake3: ignored (reached end-of-life)
59
 
trusty_ioquake3: not-affected (1.36+u20140116+gdde36d9-1)
60
 
utopic_ioquake3: ignored (reached end-of-life)
61
 
vivid_ioquake3: ignored (reached end-of-life)
62
 
vivid/stable-phone-overlay_ioquake3: DNE
63
 
vivid/ubuntu-core_ioquake3: DNE
64
 
wily_ioquake3: ignored (reached end-of-life)
65
 
xenial_ioquake3: not-affected (1.36+u20160122+dfsg1-1)
66
 
yakkety_ioquake3: not-affected (1.36+u20160616+dfsg1-1)
67
 
zesty_ioquake3: not-affected
68
 
artful_ioquake3: not-affected
69
 
bionic_ioquake3: not-affected
70
 
devel_ioquake3: not-affected