AVG-227 log

Package urbanterror
Status Unknown
Severity Critical
Type arbitrary code execution
Affected 2:4.3.2-2
Fixed Unknown
Current Removed
Ticket None
Created Thu Mar 23 18:18:36 2017
Issue Severity Remote Type Description
CVE-2017-6903 Critical Yes Arbitrary code execution
The current version of ioquake3 (and its forks) receive arbitrary files from server and load them in the context of the ioq3 client. If a malicious attacker...
References
https://github.com/Barbatos/ioq3-for-UrbanTerror-4/issues/71
https://github.com/Barbatos/ioq3-for-UrbanTerror-4/pull/73
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857699
Notes
Package dropped from repository