Bug 577810 (CVE-2010-3439)
Summary: | CVE-2010-3439 alienarena: Two security issues in Quake II 3.20 (Server) (applicable to alienarena) | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | hdegoede, tcallawa |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.quakedev.com/forums/index.php?topic=53.0 | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2010-12-16 21:38:12 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Jan Lieskovsky
2010-03-29 10:33:40 UTC
These issues affect the versions of the alienarena package, as shipped with Fedora release of 11 and 12. Please fix (once the patch for second issue is available). Reply from Richard Stanway regarding the proposed fix: [7] http://www.openwall.com/lists/oss-security/2010/03/29/5 Cmd_TokenizeString (s, false) is used in alienarena's sv_user.c, so the second issue does not appear to be applicable. alienarena-7.32-3.fc12.2 has been submitted as an update for Fedora 12. http://admin.fedoraproject.org/updates/alienarena-7.32-3.fc12.2 alienarena-7.32-3.fc11 has been submitted as an update for Fedora 11. http://admin.fedoraproject.org/updates/alienarena-7.32-3.fc11 alienarena-7.33-2.fc13 has been submitted as an update for Fedora 13. http://admin.fedoraproject.org/updates/alienarena-7.33-2.fc13 alienarena-7.32-3.fc12.2 has been pushed to the Fedora 12 stable repository. If problems still persist, please make note of it in this bug report. alienarena-7.32-3.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report. alienarena-7.33-2.fc13 has been pushed to the Fedora 13 stable repository. If problems still persist, please make note of it in this bug report. This is CVE-2010-3439 |