Bug#681812: openarena-server: segfaults when a client is requesting a callvote to kick another player

Simon McVittie smcv at debian.org
Fri Sep 14 07:17:42 UTC 2012


severity 681812 serious
thanks

On Mon, 16 Jul 2012 at 20:54:41 +0200, Markus Koschany wrote:
> 1. Join the server and open the ingame console with Shift+ESC or ~.
> 2. Ask for a vote to kick a non-existing player on the server like
> 
> \callvote kick pullo
> 
> if pullo is a player who does not play on the server.

Hi, sorry for the delay in responding to this. Thank you both for your help
with this bug.

This is a DoS that remote unauthenticated users can trigger on-demand, so
I've bumped the severity up and am preparing an upload.
I'll ask for a freeze exception for it.

Regards,
    S



More information about the Pkg-games-devel mailing list