server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote attackers to cause a denial of service (network traffic amplification) via a spoofed (1) getstatus or (2) rcon request.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "1.36+u20140116+gdde36d9-1", "binary_name": "ioquake3" }, { "binary_version": "1.36+u20140116+gdde36d9-1", "binary_name": "ioquake3-dbg" }, { "binary_version": "1.36+u20140116+gdde36d9-1", "binary_name": "ioquake3-server" } ] }