{"id":"DEBIAN-CVE-2017-6903","details":"In ioquake3 before 2017-03-14, the auto-downloading feature has insufficient content restrictions. This also affects Quake III Arena, OpenArena, OpenJK, iortcw, and other id Tech 3 (aka Quake 3 engine) forks. A malicious auto-downloaded file can trigger loading of crafted auto-downloaded files as native code DLLs. A malicious auto-downloaded file can contain configuration defaults that override the user's. Executable bytecode in a malicious auto-downloaded file can set configuration variables to values that will result in unwanted native code DLLs being loaded, resulting in sandbox escape.","modified":"2026-09-01T20:03:49.681461602Z","published":"2017-03-14T22:59:01.257Z","upstream":["CVE-2017-6903"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2017-6903"}],"affected":[{"package":{"name":"ioquake3","ecosystem":"Debian:12","purl":"pkg:deb/debian/ioquake3?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.36+u20161101+dfsg1-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-6903.json"}},{"package":{"name":"ioquake3","ecosystem":"Debian:13","purl":"pkg:deb/debian/ioquake3?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.36+u20161101+dfsg1-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-6903.json"}},{"package":{"name":"ioquake3","ecosystem":"Debian:14","purl":"pkg:deb/debian/ioquake3?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.36+u20161101+dfsg1-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-6903.json"}},{"package":{"name":"iortcw","ecosystem":"Debian:12","purl":"pkg:deb/debian/iortcw?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.50a+dfsg1-3"}]}],"versions":["1.42b+20150930+dfsg1-1","1.42b+20151119+dfsg1-1","1.42d+dfsg1-1","1.42d+dfsg1-2","1.42d+dfsg1-3","1.42d+dfsg1-4","1.42d+dfsg1-5","1.50a+dfsg1-1","1.50a+dfsg1-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-6903.json"}},{"package":{"name":"iortcw","ecosystem":"Debian:13","purl":"pkg:deb/debian/iortcw?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.50a+dfsg1-3"}]}],"versions":["1.42b+20150930+dfsg1-1","1.42b+20151119+dfsg1-1","1.42d+dfsg1-1","1.42d+dfsg1-2","1.42d+dfsg1-3","1.42d+dfsg1-4","1.42d+dfsg1-5","1.50a+dfsg1-1","1.50a+dfsg1-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-6903.json"}},{"package":{"name":"iortcw","ecosystem":"Debian:14","purl":"pkg:deb/debian/iortcw?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.50a+dfsg1-3"}]}],"versions":["1.42b+20150930+dfsg1-1","1.42b+20151119+dfsg1-1","1.42d+dfsg1-1","1.42d+dfsg1-2","1.42d+dfsg1-3","1.42d+dfsg1-4","1.42d+dfsg1-5","1.50a+dfsg1-1","1.50a+dfsg1-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-6903.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}