Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 627236 (CVE-2017-11721) - games-fps/quake3: Buffer overflow in MSG_ReadBits/MSG_WriteBits
Summary: games-fps/quake3: Buffer overflow in MSG_ReadBits/MSG_WriteBits
Status: RESOLVED FIXED
Alias: CVE-2017-11721
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [upstream/ebuild cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-08-07 13:09 UTC by Agostino Sarubbo
Modified: 2019-12-08 21:31 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2017-08-07 13:09:42 UTC
From ${URL} :

Buffer overflow in ioquake3 before 2017-08-02 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted packet.

Upstream patch:

https://github.com/ioquake/ioq3/commit/d2b1d124d4055c2fcbe5126863487c52fd58cca1


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Larry the Git Cow gentoo-dev 2019-12-08 21:31:03 UTC
The bug has been closed via the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=9e2a01c4881b67200d0a43ab7d6f147d6e5ac2aa

commit 9e2a01c4881b67200d0a43ab7d6f147d6e5ac2aa
Author:     Aaron Bauman <bman@gentoo.org>
AuthorDate: 2019-12-08 21:29:54 +0000
Commit:     Aaron Bauman <bman@gentoo.org>
CommitDate: 2019-12-08 21:29:54 +0000

    games-fps/quake3*: drop vulnerable pkgs
    
    Closes: https://bugs.gentoo.org/420783
    Closes: https://bugs.gentoo.org/606696
    Closes: https://bugs.gentoo.org/627236
    
    Signed-off-by: Aaron Bauman <bman@gentoo.org>

 games-fps/openarena/Manifest                       |   2 -
 .../openarena/files/openarena-0.8.8-makefile.patch |  36 -----
 .../files/openarena-0.8.8-unbundling.patch         | 104 -------------
 games-fps/openarena/metadata.xml                   |  14 --
 games-fps/openarena/openarena-0.8.8-r1.ebuild      |  85 -----------
 games-fps/quake3-alliance/Manifest                 |   2 -
 games-fps/quake3-alliance/metadata.xml             |   8 -
 .../quake3-alliance/quake3-alliance-3.3-r1.ebuild  |  23 ---
 games-fps/quake3-alternatefire/Manifest            |   1 -
 games-fps/quake3-alternatefire/files/server.cfg    | 109 --------------
 games-fps/quake3-alternatefire/metadata.xml        |   8 -
 .../quake3-alternatefire-2.0-r1.ebuild             |  17 ---
 games-fps/quake3-bfp/Manifest                      |   1 -
 games-fps/quake3-bfp/metadata.xml                  |   8 -
 games-fps/quake3-bfp/quake3-bfp-1.2-r1.ebuild      |  17 ---
 games-fps/quake3-bin/Manifest                      |   2 -
 games-fps/quake3-bin/files/q3ded.conf.d            |   5 -
 games-fps/quake3-bin/files/q3ded.rc                |  34 -----
 games-fps/quake3-bin/metadata.xml                  |  24 ---
 games-fps/quake3-bin/quake3-bin-1.32c-r2.ebuild    | 105 -------------
 games-fps/quake3-cpma/Manifest                     |   2 -
 games-fps/quake3-cpma/files/server.cfg             | 146 ------------------
 games-fps/quake3-cpma/metadata.xml                 |  37 -----
 games-fps/quake3-cpma/quake3-cpma-1.48.ebuild      |  26 ----
 games-fps/quake3-data/Manifest                     |   1 -
 games-fps/quake3-data/metadata.xml                 |   8 -
 games-fps/quake3-data/quake3-data-1.32b.ebuild     |  54 -------
 games-fps/quake3-defrag/Manifest                   |  13 --
 games-fps/quake3-defrag/metadata.xml               |   8 -
 .../quake3-defrag/quake3-defrag-1.91.21.ebuild     |  44 ------
 games-fps/quake3-demo/Manifest                     |   1 -
 games-fps/quake3-demo/metadata.xml                 |  11 --
 games-fps/quake3-demo/quake3-demo-1.11-r1.ebuild   |  62 --------
 games-fps/quake3-excessiveplus/Manifest            |   1 -
 games-fps/quake3-excessiveplus/metadata.xml        |  20 ---
 .../quake3-excessiveplus-2.3.ebuild                |  22 ---
 games-fps/quake3-lrctf/Manifest                    |   1 -
 games-fps/quake3-lrctf/metadata.xml                |   8 -
 games-fps/quake3-lrctf/quake3-lrctf-1.1.ebuild     |  16 --
 games-fps/quake3-matrix/Manifest                   |   1 -
 games-fps/quake3-matrix/metadata.xml               |   8 -
 .../quake3-matrix/quake3-matrix-2.4_beta-r1.ebuild |  22 ---
 games-fps/quake3-nsco/Manifest                     |   2 -
 games-fps/quake3-nsco/files/server.cfg             |  97 ------------
 games-fps/quake3-nsco/metadata.xml                 |  29 ----
 games-fps/quake3-nsco/quake3-nsco-1.93-r1.ebuild   |  22 ---
 games-fps/quake3-osp/Manifest                      |   1 -
 games-fps/quake3-osp/files/server.cfg              | 165 ---------------------
 games-fps/quake3-osp/metadata.xml                  |   8 -
 games-fps/quake3-osp/quake3-osp-1.03a-r1.ebuild    |  22 ---
 games-fps/quake3-ra3/Manifest                      |   1 -
 games-fps/quake3-ra3/metadata.xml                  |   8 -
 games-fps/quake3-ra3/quake3-ra3-1.76-r1.ebuild     |  18 ---
 games-fps/quake3-reaction/Manifest                 |   2 -
 games-fps/quake3-reaction/metadata.xml             |   8 -
 .../quake3-reaction/quake3-reaction-3.2.ebuild     |  20 ---
 games-fps/quake3-ruinhunters/Manifest              |   2 -
 games-fps/quake3-ruinhunters/metadata.xml          |   8 -
 .../quake3-ruinhunters-1.0a-r1.ebuild              |  22 ---
 games-fps/quake3-teamarena/Manifest                |   1 -
 games-fps/quake3-teamarena/metadata.xml            |   8 -
 .../quake3-teamarena/quake3-teamarena-1.32b.ebuild |  55 -------
 games-fps/quake3-threewave/Manifest                |   2 -
 games-fps/quake3-threewave/metadata.xml            |   8 -
 .../quake3-threewave-1.7-r1.ebuild                 |  21 ---
 games-fps/quake3/Manifest                          |   1 -
 games-fps/quake3/files/quake3-1.36-bots.patch      |  20 ---
 games-fps/quake3/metadata.xml                      |  26 ----
 games-fps/quake3/quake3-1.36-r1.ebuild             | 122 ---------------
 games-fps/quake3/quake3-9999.ebuild                | 137 -----------------
 70 files changed, 1953 deletions(-)