Short Description
This updates the Win32, Linux and MacOSX editions of Return to Castle Wolfenstein: Enemy Territory to version 2.60b. This release addresses a client download leak and a buffer overflow.
CVE-2006-2082: directory traversal / information leak in Quake III Arena auto download feature
Ludwig Nussel and Thilo Shulz discovered a vulnerability letting a malicious client download files from a server if auto download is enabled ( sv_allowDownload 1 ).
A second issue fixed in this release would let a malicious server exploit a buffer overflow to execute a shellcode on connecting clients.
--
Updated binaries for the following games are available:
Quake III Arena - fixed at version 1.32c
Return To Castle Wolfenstein - fixed at version 1.41b
Wolfenstein: Enemy Territory - fixed at version 2.60b
If you run a server with any older version, please upgrade or consider turning off autodownload ( set sv_allowDownload to 0 ). Wolfenstein: Enemy Territory servers http/ftp download feature is not affected by CVE-2006-2082. If you don't wish to upgrade, you can decide to only enable http/ftp downloads and disable legacy downloads in that particular case.
Finally, server administrators should note that game servers should be running in restricted environments as much as possible ( unpriviledged accounts and chroot jails ). It's a good thing to do the same for clients, or at least ensure that you are properly firewalled.
General Behavior
Treat other members with the respect they deserve. Please do not flame or insult other users.
Posting Behavior
Please do not spam. When you make a post, please ensure it is in the relevant section and is clearly titled.
Please refrain from making multiple posts in a row.
Use the edit button function as this helps keeping the forums look tidy.
Do not post threads in all capitals since this is considered akin to shouting and is not necessary.
Please do not use profanity.
Advertising and Pornography
Advertising of other sites/services or posting links to pornography or illegal content is strictly forbidden.
Warez & Piracy
Requests for illegal content will be treated as piracy. This includes requests or provision of CD keys, cracks, serials, and pirated software, movies, or music that is protected under copyright law.
Note: If you are intending to respond to a comment, please ensure that you click 'reply' next to that comment.
Note:Click here to cancel your reply and instead post a new comment.
Note:Click here to cancel your edit and instead post a new comment.