7.8
CVSSv2

CVE-2010-5077

Published: 27/10/2014 Updated: 29/10/2014
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote malicious users to cause a denial of service (network traffic amplification) via a spoofed (1) getstatus or (2) rcon request.

Vulnerable Product Search on Vulmon Subscribe to Product

tremulous tremulous

openarena openarena

ioquake3 ioquake3 engine

Vendor Advisories

Debian Bug report logs - #665656 openarena-server: [CVE-2010-5077] traffic amplification via getstatus requests Package: openarena-server; Maintainer for openarena-server is Debian Games Team <pkg-games-devel@listsaliothdebianorg>; Source for openarena-server is src:openarena (PTS, buildd, popcon) Reported by: Markus Kosc ...