CVE-2010-5077

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
27/10/2014
Last modified:
12/04/2025

Description

server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote attackers to cause a denial of service (network traffic amplification) via a spoofed (1) getstatus or (2) rcon request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ioquake3:ioquake3_engine:*:*:*:*:*:*:*:* r1761 (including)
cpe:2.3:a:openarena:openarena:*:*:*:*:*:*:*:*
cpe:2.3:a:tremulous:tremulous:*:*:*:*:*:*:*:*