e48355d7-1548-11e7-8611-0090f5f2f347id Tech 3 -- remote code execution vulnerability

The content auto-download of id Tech 3 can be used to deliver maliciously crafted content, that triggers downloading of further content and loading and executing it as native code with user credentials. This affects ioquake3, ioUrbanTerror, OpenArena, the original Quake 3 Arena and other forks.

Discovery 2017-03-14
Entry 2017-04-07
lt 1.36_16

lt g2930

lt 4.3.2,1

lt 0.8.8.s1910_3,1