Boletines de Vulnerabilidades

DSA-3812 ioquake3 - security update


Información sobre el sistema

   
Software afectado Debian

Descripción

It was discovered that ioquake3, a modified version of the ioQuake3 gameengine performs insufficent restrictions on automatically downloadedcontent (pk3 files or game code), which allows malicious game servers tomodify configuration settings including driver settings.

More info:

https://www.debian.org/security/2017/dsa-3812

Identificadores estándar

Propiedad Valor
CVE CVE-2017-6903 and DSA-3812.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2017-03-19

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT