id Software has released patches for Quake III Arena, Return To Castle Wolfenstein and Wolfenstein: Enemy Territory that fix two security vulnerabilities found since the GPL release of the Quake3 source code.

The patches include an updated game binary for each specific operating system (ex Quake3.exe). Links to download the very small patches can be found below.



-Ludwig Nussel and Thilo Shulz discovered a vulnerability letting a malicious client download files from a server if auto download is enabled ( sv_allowDownload 1 ).

-A second issue fixed in this release would let a malicious server exploit a buffer overflow to execute a shellcode on connecting clients.