Another critical Q3 security bug

Locked
Ganemi
Posts: 564
Joined: Thu Apr 21, 2005 12:57 pm

Re: Another critical Q3 security bug

Post by Ganemi »

riddla wrote:http://aluigi.altervista.org/adv/q3cfilevar-adv.txt

pfffffft. wonder if id will ever realize how cool it would be to work with the icculus guys and release a cock-solid PR for a change...
*whispers* With ragdolls.

*dodges a tomato*
dzjepp
Posts: 12839
Joined: Wed Mar 28, 2001 8:00 am

Post by dzjepp »

Yeah, syncerror, if id brings out a new patch, could you guys mebbe ask the icculus guys if you can merge their exe into an official id exe?
Timbo
Posts: 171
Joined: Sat Jun 10, 2000 7:00 am

Post by Timbo »

The recent 1.32c patch WAS derived from ioq3 (the specific fixes were permitted to be committed to the closed version as well as the GPL version). The ioq3 changes couldn't ever be released by id, unless permission was granted from ALL the contributors.
dzjepp
Posts: 12839
Joined: Wed Mar 28, 2001 8:00 am

Post by dzjepp »

Are there a ton of ioq3 contributors?
User avatar
Foo
Posts: 13840
Joined: Thu Aug 03, 2000 7:00 am
Location: New Zealand

Post by Foo »

dzjepp
Posts: 12839
Joined: Wed Mar 28, 2001 8:00 am

Post by dzjepp »

So where the specific 1.32c fixes under obligation to be premitted by everyone that contributed to ioq3? Meaning if so, it wouldn't be too far fetched or impossible to get such an appraisal going for a full scale ioq3 merger with an id patch? :paranoid:
User avatar
Foo
Posts: 13840
Joined: Thu Aug 03, 2000 7:00 am
Location: New Zealand

Post by Foo »

I think the fixes specific to that were few in number, and from contributors still around and available to give permission. It's a different situation between the specific fixes they rolled into both, and the entire list of changes in IO.
"Maybe you have some bird ideas. Maybe that’s the best you can do."
― Terry A. Davis
Kat
Posts: 952
Joined: Tue Nov 14, 2000 8:00 am

Post by Kat »

Am I reading that right, the bug only effects machines if autodownload is active? And you need to connect to a machine with the hack in place for it to do anything?
[url=https://www.katsbits.com/tutorials#q3w]Tutorials, tools and resources[/url]
^misantropia^
Posts: 4022
Joined: Sat Mar 12, 2005 6:24 pm

Post by ^misantropia^ »

This is correct, yes.
Oeloe
Posts: 1529
Joined: Fri Mar 19, 2004 8:00 am

Post by Oeloe »

^^^^ Hi there, fellow lurker. ;)
^misantropia^
Posts: 4022
Joined: Sat Mar 12, 2005 6:24 pm

Post by ^misantropia^ »

Have we met, sir?




(not quite a lurker, you, Oeloe. I remember your postcount being at least several hundred less than what I had when I left)
Locked