jedi-academy/codemp/client
Jonathan Gray 832b4342a8 CVE-2006-2236 Buffer overflow in the Quake 3 Engine
CVE-2006-2236
Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60,
(2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b
allows remote attackers to execute arbitrary commands via a long
remapShader command.

from Thilo Schulz in ioquake3
svn 765 git d21411452ef32b86c0b79ddcaf49221701dcdb07

Add string length checking to function COM_StripExtension. This fixes
the R_RemapShader buffer overflow exploit that can be found here:
http://milw0rm.com/exploits/1750
2013-05-07 22:18:45 +10:00
..
eax ditch dos style newlines 2013-04-23 15:21:39 +10:00
OpenAL ditch dos style newlines 2013-04-23 15:21:39 +10:00
0_SH_Leak.cpp fix slashes in include paths 2013-04-23 15:40:23 +10:00
BinkVideo.cpp ditch dos style newlines 2013-04-23 15:21:39 +10:00
BinkVideo.h ditch dos style newlines 2013-04-23 15:21:39 +10:00
cl_cgame.cpp fix #includes to compile on non windows without pch 2013-04-25 23:51:46 +10:00
cl_cin.cpp add some casts so gcc can pick an overloaded abs/max/min func 2013-04-25 23:51:53 +10:00
cl_cin_console.cpp ditch dos style newlines 2013-04-23 15:21:39 +10:00
cl_console.cpp ditch dos style newlines 2013-04-23 15:21:39 +10:00
cl_input.cpp add some casts so gcc can pick an overloaded abs/max/min func 2013-04-25 23:51:53 +10:00
cl_keys.cpp const fixes 2013-05-02 13:47:51 +10:00
cl_main.cpp Fix to multiple buffer overflow bugs in CL_Rcon_f 2013-05-07 22:18:44 +10:00
cl_net_chan.cpp ditch dos style newlines 2013-04-23 15:21:39 +10:00
cl_parse.cpp fix #includes to compile on non windows without pch 2013-04-25 23:51:46 +10:00
cl_scrn.cpp ditch dos style newlines 2013-04-23 15:21:39 +10:00
cl_ui.cpp ditch dos style newlines 2013-04-23 15:21:39 +10:00
client.h const fixes 2013-05-02 13:47:51 +10:00
fffx.h ditch dos style newlines 2013-04-23 15:21:39 +10:00
FXExport.cpp fix #includes to compile on non windows without pch 2013-04-25 23:51:46 +10:00
FXExport.h ditch dos style newlines 2013-04-23 15:21:39 +10:00
FxPrimitives.cpp provide a gcc style alternative to the inline asm in FxPrimitives 2013-04-25 23:51:53 +10:00
FxPrimitives.h avoid extra qualification of function members 2013-04-26 22:27:24 +10:00
FxScheduler.cpp CVE-2006-2236 Buffer overflow in the Quake 3 Engine 2013-05-07 22:18:45 +10:00
FxScheduler.h stricmp -> Q_stricmp 2013-04-25 23:51:55 +10:00
FxSystem.cpp ditch dos style newlines 2013-04-23 15:21:39 +10:00
FxSystem.h avoid extra qualification of function members 2013-04-26 22:27:24 +10:00
FxTemplate.cpp stricmp -> Q_stricmp 2013-04-25 23:51:55 +10:00
FxUtil.cpp ditch dos style newlines 2013-04-23 15:21:39 +10:00
FxUtil.h ditch dos style newlines 2013-04-23 15:21:39 +10:00
keycodes.h ditch dos style newlines 2013-04-23 15:21:39 +10:00
keys.h ditch dos style newlines 2013-04-23 15:21:39 +10:00
snd_ambient.cpp stricmp -> Q_stricmp 2013-04-25 23:51:55 +10:00
snd_ambient.h ditch dos style newlines 2013-04-23 15:21:39 +10:00
snd_dma.cpp CVE-2006-2236 Buffer overflow in the Quake 3 Engine 2013-05-07 22:18:45 +10:00
snd_dma_console.cpp ditch dos style newlines 2013-04-23 15:21:39 +10:00
snd_local.h fix #includes to compile on non windows without pch 2013-04-25 23:51:46 +10:00
snd_local_console.h ditch dos style newlines 2013-04-23 15:21:39 +10:00
snd_mem.cpp strnicmp -> Q_strnicmp 2013-04-25 23:51:56 +10:00
snd_mem_console.cpp ditch dos style newlines 2013-04-23 15:21:39 +10:00
snd_mix.cpp opt out of more masm assembly 2013-04-25 23:51:56 +10:00
snd_mp3.cpp ditch dos style newlines 2013-04-23 15:21:39 +10:00
snd_mp3.h ditch dos style newlines 2013-04-23 15:21:39 +10:00
snd_music.cpp stricmp -> Q_stricmp 2013-04-25 23:51:55 +10:00
snd_music.h ditch dos style newlines 2013-04-23 15:21:39 +10:00
snd_public.h ditch dos style newlines 2013-04-23 15:21:39 +10:00