In ioquake3 before 2017-03-14, the auto-downloading feature has insufficient content restrictions. This also affects Quake III Arena, OpenArena, OpenJK, iortcw, and other id Tech 3 (aka Quake 3 engine) forks. A malicious auto-downloaded file can trigger loading of crafted auto-downloaded files as native code DLLs. A malicious auto-downloaded file can contain configuration defaults that override the user's. Executable bytecode in a malicious auto-downloaded file can set configuration variables to values that will result in unwanted native code DLLs being loaded, resulting in sandbox escape.
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "2017-02-27"
}
],
"cpe": "cpe:2.3:a:ioquake3:ioquake3:*:*:*:*:*:*:*:*"
},
{
"source": "DESCRIPTION",
"extracted_events": [
{
"introduced": "ioquake3"
},
{
"fixed": "2017-03-14"
}
]
}
]
}