server/sv_main.c in Quake3 Arena, as used in ioquake3...
High severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Apr 12, 2025
Description
Published by the National Vulnerability Database
Oct 27, 2014
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Apr 12, 2025
server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote attackers to cause a denial of service (network traffic amplification) via a spoofed (1) getstatus or (2) rcon request.
References