Bug 806898 (CVE-2010-5077)
Summary: | CVE-2010-5077 quake3: DDoS via getstatus and rcon requests | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | jkaluza, lxtnow, metherid |
Target Milestone: | --- | Keywords: | Reopened, Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2012-09-04 21:59:35 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 806980 | ||
Bug Blocks: |
Description
Jan Lieskovsky
2012-03-26 13:02:20 UTC
This issue did NOT affect the current versions of the quake3 package, as shipped with Fedora release of 15 and 16 (those versions already contain upstream patch preventing this deficiency). This issue does seem to affect Tremulous 1.2beta1 which we ship in Fedora (the patch is unapplied there). Originally reported via http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=665842 Created tremulous tracking bugs for this issue Affects: fedora-all [bug 806980] This issue has been assigned the name CVE-2010-5077. tremulous-1.2.0-0.5.beta1.fc16 has been pushed to the Fedora 16 stable repository. If problems still persist, please make note of it in this bug report. tremulous-1.2.0-0.5.beta1.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report. |