Quake 3 Engine contains a flaw that may allow a remote denial of service. The issue is triggered when a remote attacker sends a specially crafted getstatus UDP request to the server, which will result in loss of availability for the server.
Classification
Location:
Remote / Network Access
Attack Type:
Denial of Service
Impact:
Loss of Availability
Solution:
Patch / RCS,
Upgrade
Exploit:
Exploit Public
Disclosure:
Vendor Verified
Solution
Multiple vendors which bundle the engine have released upgrades for this vulnerability. ioquake3 patched this in SVN revision 1762, but has not released a formal version upgrade.