Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Victor Roemer
FYI, The ioquake3.org blog post was updated to reference me as the reporter. On Tue, Mar 14, 2017 at 4:42 PM, Victor Roemer wrote: > Any way we can amend that? > > On Tue, Mar 14, 2017 at 3:31 PM, Simon McVittie wrote: > >> On Tue, 14 Mar 2017 at 13:38:37 -0400, Victor Roemer wrote: >> > I orig

Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Victor Roemer
Any way we can amend that? On Tue, Mar 14, 2017 at 3:31 PM, Simon McVittie wrote: > On Tue, 14 Mar 2017 at 13:38:37 -0400, Victor Roemer wrote: > > I originally reported the vulnerability to ioquake3. I'd like to help > with the > > CVE however I can. > > I'm not familiar with CVE reports which

Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Simon McVittie
On Tue, 14 Mar 2017 at 13:38:37 -0400, Victor Roemer wrote: > I originally reported the vulnerability to ioquake3. I'd like to help with the > CVE however I can. > I'm not familiar with CVE reports which is why one hasn't already been > written. MITRE's new process really doesn't help matters the

Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Victor Roemer
Hi guys, I originally reported the vulnerability to ioquake3. I'd like to help with the CVE however I can. I'm not familiar with CVE reports which is why one hasn't already been written. Thanks, Victor

Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Daniel Gibson
Hi, I heard upstream is not gonna create a CVE, so go ahead.. Cheers, Daniel On 14.03.2017 17:44, Salvatore Bonaccorso wrote: Hi Simon, On Tue, Mar 14, 2017 at 08:30:36AM +, Simon McVittie wrote: cc'ing security team for information. No CVE ID yet, I assume ioquake3 upstream will be requ

Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Salvatore Bonaccorso
Hi Simon, On Tue, Mar 14, 2017 at 08:30:36AM +, Simon McVittie wrote: > cc'ing security team for information. No CVE ID yet, I assume ioquake3 > upstream will be requesting one (or if not I will). heard anything about that yet? If so can you request a CVE via https://cveform.mitre.org/ and lo

Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Daniel Gibson
On 14.03.2017 09:30, Simon McVittie wrote: Thanks for reporting, I'll fix this ASAP. Awesome, thanks for the prompt reaction! Looks like I need to teach ioquake3 upstream about coordinated disclosure, or remind them that their game is in distributions. That might be a good idea, I had th

Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Moritz Muehlenhoff
On Tue, Mar 14, 2017 at 12:18:27PM +, Simon McVittie wrote: > On Tue, 14 Mar 2017 at 08:30:36 +, Simon McVittie wrote: > > On Tue, 14 Mar 2017 at 04:59:15 +0100, Daniel Gibson wrote: > > > earlier today ioquake3 fixed a vulnerability that, as far as I understand, > > > could let malicious m

Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Simon McVittie
On Tue, 14 Mar 2017 at 08:30:36 +, Simon McVittie wrote: > On Tue, 14 Mar 2017 at 04:59:15 +0100, Daniel Gibson wrote: > > earlier today ioquake3 fixed a vulnerability that, as far as I understand, > > could let malicious multiplayer servers execute code on connecting clients. > > It affects al

Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Simon McVittie
Control: tags 857699 + security Control: clone 857699 -2 -3 Control: reassign -2 iortcw 1.42b+20150930+dfsg1-1 Control: reassign -3 openjk 0~20150430+dfsg1-1 On Tue, 14 Mar 2017 at 04:59:15 +0100, Daniel Gibson wrote: > earlier today ioquake3 fixed a vulnerability that, as far as I understand, > c

Bug#857699: ioquake3 has a security vulnerability

2017-03-13 Thread Daniel Gibson
Package: ioquake3 Version: 1.36 Severity: grave Hi, earlier today ioquake3 fixed a vulnerability that, as far as I understand, could let malicious multiplayer servers execute code on connecting clients. It affects all prior versions of ioquake3 (and I think also original Quake 3). Details: h