Tremulous: User-assisted execution of arbitrary code — GLSA 200901-06

A buffer overflow vulnerability has been discovered in Tremulous.

Affected packages

games-fps/tremulous on all architectures
Affected versions < 1.1.0-r2
Unaffected versions >= 1.1.0-r2
games-fps/tremulous-bin on all architectures
Affected versions < 1.1.0
Unaffected versions

Background

Tremulous is a team-based First Person Shooter game.

Description

It has been reported that Tremulous includes a vulnerable version of the ioQuake3 engine (GLSA 200605-12, CVE-2006-2236).

Impact

A remote attacker could entice a user to connect to a malicious games server, possibly resulting in the execution of arbitrary code with the privileges of the user running the application.

Workaround

There is no known workaround at this time.

Resolution

Tremulous users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=games-fps/tremulous-1.1.0-r2"

Note: The binary version of Tremulous has been removed from the Portage tree.

References

Release date
January 11, 2009

Latest revision
January 11, 2009: 01

Severity
normal

Exploitable
remote

Bugzilla entries