Tremulous: User-assisted execution of arbitrary code
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200901-06 / tremulous tremulous-bin |
| Release Date |
January 11, 2009 |
| Latest Revision |
January 11, 2009: 01 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| games-fps/tremulous |
<
1.1.0-r2 |
>=
1.1.0-r2 |
All supported architectures
|
| games-fps/tremulous-bin |
<
1.1.0 |
|
All supported architectures
|
Related bugreports:
#222119
Synopsis
A buffer overflow vulnerability has been discovered in Tremulous.
2.
Impact Information
Background
Tremulous is a team-based First Person Shooter game.
Description
It has been reported that Tremulous includes a vulnerable version of
the ioQuake3 engine (GLSA 200605-12, CVE-2006-2236).
Impact
A remote attacker could entice a user to connect to a malicious games
server, possibly resulting in the execution of arbitrary code with the
privileges of the user running the application.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
Tremulous users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=games-fps/tremulous-1.1.0-r2"
|
Note: The binary version of Tremulous has been removed from the Portage
tree.
4.
References
|