UBUNTU-CVE-2017-6903

Source
https://ubuntu.com/security/CVE-2017-6903
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-6903.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2017-6903
Related
Published
2017-03-14T22:59:00Z
Modified
2025-01-13T10:21:21Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In ioquake3 before 2017-03-14, the auto-downloading feature has insufficient content restrictions. This also affects Quake III Arena, OpenArena, OpenJK, iortcw, and other id Tech 3 (aka Quake 3 engine) forks. A malicious auto-downloaded file can trigger loading of crafted auto-downloaded files as native code DLLs. A malicious auto-downloaded file can contain configuration defaults that override the user's. Executable bytecode in a malicious auto-downloaded file can set configuration variables to values that will result in unwanted native code DLLs being loaded, resulting in sandbox escape.

References

Affected packages

Ubuntu:Pro:16.04:LTS / ioquake3

Package

Name
ioquake3
Purl
pkg:deb/ubuntu/ioquake3@1.36+u20160122+dfsg1-1?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.36+u20150710+dfsg1-1
1.36+u20150926+dfsg1-1
1.36+u20151017+dfsg1-1
1.36+u20160122+dfsg1-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:18.04:LTS / ioquake3

Package

Name
ioquake3
Purl
pkg:deb/ubuntu/ioquake3@1.36+u20180108~dfsg-2?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.36+u20180108~dfsg-2

Affected versions

1.*

1.36+u20170803+dfsg1-1
1.36+u20171016~dfsg-1
1.36+u20171122~dfsg-1
1.36+u20171216~dfsg-1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.36+u20180108~dfsg-2",
            "binary_name": "ioquake3"
        },
        {
            "binary_version": "1.36+u20180108~dfsg-2",
            "binary_name": "ioquake3-dbgsym"
        },
        {
            "binary_version": "1.36+u20180108~dfsg-2",
            "binary_name": "ioquake3-server"
        },
        {
            "binary_version": "1.36+u20180108~dfsg-2",
            "binary_name": "ioquake3-server-dbgsym"
        }
    ]
}