Title: Quake III Arena 1.32c Binaries (And for iD Q3A based-games) Post by: Lopson on 2006-07-10, 10:17 A binary patch has been released by iD for the following games: Quake III Arena, Wolfenstein : Enemy Territory, Return to Castle Wolfenstein. Readme is here:
Code: CVE-2006-2082: directory traversal / information leak in Quake III Arena auto download feature The most weird thing is that there is nothing in the iD software site regarding this, but it is an official patch made by iD Software. Phoenix, please take a look at this so that you can correct this in the generations exe that you are compiling. Title: Re: Quake III Arena 1.32c Binaries Post by: Phoenix on 2006-07-10, 15:01 Thanks for the post. I've been aware of the R_RemapShaders buffer overflow vulnerability, but I was not aware of this notice. The fix will be implemented in the upcoming Generations binary. Currently we have autodownloading disabled on Central and Euro, so this poses no threat to our existing stable Gen servers. As soon as the binary is available I would recommend everyone patching to 1.32c.
Title: Re: Quake III Arena 1.32c Binaries Post by: Lopson on 2006-07-11, 15:03 On a sidenote: The Punkbuster Client for these games have recieved a patch regarding some issues caused by this patch. In case you don't know the drill:
PBSETUP.EXE (http://www.evenbalance.com/index.php?page=pbsetup.php) EDIT: Also, a link for the patch. YOU MUST HAVE 1.32b INSTALLED: Patch 1.32c (http://www.planetquake3.net/download.php?op=fileid&lid=2231) |