Index: security/vuxml/vuln.xml =================================================================== --- security/vuxml/vuln.xml +++ security/vuxml/vuln.xml @@ -58,6 +58,45 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + id Tech 3 -- remote code execution vulnerability + + + ioquake3 + 1.36_16 + + + ioquake3-devel + g2930 + + + iourbanterror + 4.3.2,1 + + + openarena + 0.8.8.s1910_3,1 + + + + +

The content auto-download of id Tech 3 can be used to deliver + maliciously crafted content, that triggers downloading of + further content and loading and executing it as native code + with user credentials. This affects ioquake3, ioUrbanTerror, + OpenArena, the original Quake 3 Arena and other forks.

+ +
+ + CVE-2017-6903 + https://ioquake3.org/2017/03/13/important-security-update-please-update-ioquake3-immediately/ + + + 2017-03-14 + 2017-03-30 + +
+ chromium -- multiple vulnerabilities