sys/sys_unix.c in the ioQuake3 engine on Unix and Linux, as used in World of Padman 1.5.x before 1.5.1.1 and OpenArena 0.8.x-15 and 0.8.x-16, allows remote game servers to execute arbitrary commands via shell metacharacters in a long fs_game variable.
References
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2011-08-04 02:45
Updated : 2024-02-04 17:54
NVD link : CVE-2011-1412
Mitre link : CVE-2011-1412
CVE.ORG link : CVE-2011-1412
JSON object : View
Products Affected
openarena
- openarena
ioquake3
- ioquake3_engine
worldofpadman
- world_of_padman
linux
- linux_kernel
CWE
CWE-20
Improper Input Validation