In ioquake3 before 2017-03-14, the auto-downloading feature has insufficient content restrictions
Published Mar 14, 2017
7.8
HIGHCVSS 3.0
EPSS 1.29%
Description
In ioquake3 before 2017-03-14, the auto-downloading feature has insufficient content restrictions. This also affects Quake III Arena, OpenArena, OpenJK, iortcw, and other id Tech 3 (aka Quake 3 engine) forks. A malicious auto-downloaded file can trigger loading of crafted auto-downloaded files as native code DLLs. A malicious auto-downloaded file can contain configuration defaults that override the user's. Executable bytecode in a malicious auto-downloaded file can set configuration variables to values that will result in unwanted native code DLLs being loaded, resulting in sandbox escape.
Affected products
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AV:N/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.29% (0.01291) | 69.19th | v5 (v2026.06.15) |
| Sep 22, 2026 | 1.29% (0.01291) | 68.97th | v5 (v2026.06.15) |
| Sep 21, 2026 | 3.51% (0.03513) | 88.70th | v5 (v2026.06.15) |
| Sep 6, 2026 | 1.29% (0.01291) | 68.34th | v5 (v2026.06.15) |
| Sep 5, 2026 | 3.51% (0.03513) | 88.45th | v5 (v2026.06.15) |
| Aug 30, 2026 | 1.29% (0.01291) | 68.22th | v5 (v2026.06.15) |
| Aug 28, 2026 | 3.51% (0.03513) | 88.37th | v5 (v2026.06.15) |
| Aug 24, 2026 | 1.29% (0.01291) | 68.05th | v5 (v2026.06.15) |
| Aug 23, 2026 | 3.51% (0.03513) | 88.33th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.29% (0.01291) | 66.38th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.12% (0.00116) | 27.89th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.21% (0.00211) | 59.99th | v3 (v2023.03.01) |
| Jun 25, 2024 | 0.18% (0.00184) | 55.85th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.18% (0.00184) | 53.84th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.54% (0.01537) | 74.52th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.54% (0.01537) | 51.33th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.27% (0.02273) | 50.89th | v5 (v2026.06.15) |
| Apr 14, 2021 | 2.27% (0.02273) | 0.00th | v1 |
No CWE recorded.
References (10)
- http://www.debian.org/security/2017/dsa-3812 vendor-advisoryx_refsource_DEBIAN
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857699 x_refsource_CONFIRMThird Party Advisory
- https://github.com/JACoders/OpenJK/commit/8956a35e7b91c4a0dd1fa6db1d28c7f0efbab2d7 x_refsource_CONFIRMIssue TrackingPatch
- https://github.com/ioquake/ioq3/commit/376267d534476a875d8b9228149c4ee18b74a4fd x_refsource_CONFIRMIssue TrackingPatch
- https://github.com/ioquake/ioq3/commit/b173ac05993f634a42be3d3535e1b158de0c3372 x_refsource_CONFIRMIssue TrackingPatch
- https://github.com/ioquake/ioq3/commit/f61fe5f6a0419ef4a88d46a128052f2e8352e85d x_refsource_CONFIRMIssue TrackingPatch
- https://github.com/iortcw/iortcw/commit/11a83410153756ae350a82ed41b08d128ff7f998 x_refsource_CONFIRMIssue TrackingPatch
- https://github.com/iortcw/iortcw/commit/b248763e4878ef12d5835ece6600be8334f67da1 x_refsource_CONFIRMIssue TrackingPatch
- https://github.com/iortcw/iortcw/commit/b6ff2bcb1e4e6976d61e316175c6d7c99860fe20 x_refsource_CONFIRMIssue TrackingPatch
- https://ioquake3.org/2017/03/13/important-security-update-please-update-ioquake3-immediately/ x_refsource_CONFIRMVendor Advisory
Change history (0)
No recorded changes yet.