jedi-academy/codemp
Jonathan Gray c0af0580aa CVE-2006-2875 Stack-based buffer overflow in CL_ParseDownload
CVE-2006-2875
Stack-based buffer overflow in the CL_ParseDownload function of Quake 3
Engine 1.32c and earlier, as used in multiple products, allows remote
attackers to execute arbitrary code via a svc_download command with
compressed data that triggers the overflow during expansion.

Luigi Auriemma q3cbof

from Thilo Schulz in ioquake3
svn 796 git 99abd01c2f5e1a181acb8623edceff10cd918751

Fix remotely exploitable parse download overflow reported by Luigi Auriemma.
See http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/046578.html
for the advisory.
2013-05-07 22:18:45 +10:00
..
botlib vsprintf -> Q_vsnprintf 2013-05-07 22:18:45 +10:00
cgame CVE-2005-0984 Buffer overflow in the G_Printf function 2013-05-07 22:18:45 +10:00
client CVE-2006-2875 Stack-based buffer overflow in CL_ParseDownload 2013-05-07 22:18:45 +10:00
encryption ditch dos style newlines 2013-04-23 15:21:39 +10:00
ff ditch dos style newlines 2013-04-23 15:21:39 +10:00
game vsprintf -> Q_vsnprintf 2013-05-07 22:18:45 +10:00
ghoul2 avoid scoped enums which was until very recently a microsoft extension 2013-04-25 23:51:57 +10:00
goblib ditch dos style newlines 2013-04-23 15:21:39 +10:00
icarus vsprintf -> Q_vsnprintf 2013-05-07 22:18:45 +10:00
jpeg-6 fix #includes to compile on non windows without pch 2013-04-25 23:51:46 +10:00
mp3code rename some files to restore the correct case 2013-04-26 22:27:19 +10:00
null vsprintf -> Q_vsnprintf 2013-05-07 22:18:45 +10:00
png ditch dos style newlines 2013-04-23 15:21:39 +10:00
qcommon vsprintf -> Q_vsnprintf 2013-05-07 22:18:45 +10:00
Ratl remove surplus tokens after preprocessor directives 2013-05-02 13:47:50 +10:00
Ravl fix some accesses beyond the end of arrays spotted via clang 2013-04-26 22:27:24 +10:00
renderer CVE-2006-2236 Buffer overflow in the Quake 3 Engine 2013-05-07 22:18:45 +10:00
RMG strupr -> Q_strupr 2013-04-26 22:27:21 +10:00
sdl const fixes 2013-05-02 13:47:51 +10:00
server vsprintf -> Q_vsnprintf 2013-05-07 22:18:45 +10:00
smartheap remove some binary libraries 2013-04-23 15:30:43 +10:00
Splines vsprintf -> Q_vsnprintf 2013-05-07 22:18:45 +10:00
strings ditch dos style newlines 2013-04-23 15:21:39 +10:00
ui vsprintf -> Q_vsnprintf 2013-05-07 22:18:45 +10:00
unix vsprintf -> Q_vsnprintf 2013-05-07 22:18:45 +10:00
win32 vsprintf -> Q_vsnprintf 2013-05-07 22:18:45 +10:00
x_botlib Deleted all the Visual SourceSafe files. 2013-04-06 20:59:34 -04:00
x_exe Deleted all the Visual SourceSafe files. 2013-04-06 20:59:34 -04:00
x_jk2cgame Deleted all the Visual SourceSafe files. 2013-04-06 20:59:34 -04:00
x_jk2game Deleted all the Visual SourceSafe files. 2013-04-06 20:59:34 -04:00
x_ui Deleted all the Visual SourceSafe files. 2013-04-06 20:59:34 -04:00
zlib32 provide a gcc style alternative to the inline asm in zlib 2013-04-26 22:27:20 +10:00
buildvms.bat Jedi Academy Release 2013-04-04 17:35:38 -05:00
cleanvms.bat Jedi Academy Release 2013-04-04 17:35:38 -05:00
CMakeLists.txt disable some noisy and mostly harmless warnings 2013-05-02 13:47:51 +10:00
CommandLine.txt Jedi Academy Release 2013-04-04 17:35:38 -05:00
install.bat Jedi Academy Release 2013-04-04 17:35:38 -05:00
installvms.bat Jedi Academy Release 2013-04-04 17:35:38 -05:00
jk2mp.vcproj Jedi Academy Release 2013-04-04 17:35:38 -05:00
JKA_mp.sln Jedi Academy Release 2013-04-04 17:35:38 -05:00
namespace_begin.h ditch dos style newlines 2013-04-23 15:21:39 +10:00
namespace_end.h remove surplus tokens after preprocessor directives 2013-05-02 13:47:50 +10:00
tonet.bat Jedi Academy Release 2013-04-04 17:35:38 -05:00
tosend.bat Jedi Academy Release 2013-04-04 17:35:38 -05:00
update_MPents.bat Jedi Academy Release 2013-04-04 17:35:38 -05:00
VU.bat Jedi Academy Release 2013-04-04 17:35:38 -05:00
WinDed.dsp Jedi Academy Release 2013-04-04 17:35:38 -05:00
WinDed.vcproj Jedi Academy Patch 1.01 2013-04-04 18:21:13 -05:00