id Software have released patches for Return to Castle Wolfenstein and Wolfenstein: Enemy Territory.
Unfortunately it seems the only change is to fix a 'security issue' which has been discovered since they released the full Quake 3 Arena source code.
It appears the patches may cause problems with mod compatibility if clients install it, though servers seem to be coping fine at least with ETPro. It appears you can mix & match clients and servers with either 2.60 or 2.60b. However, the patch fixes seperate security exploits on both client and server, so you should consider upgrading as soon as your favourite mod is compatible.
From the readme:
A [...] issue fixed in this release would let a malicious server exploit a buffer overflow to execute a shellcode on connecting clients.
If you run a server with any older version, please upgrade or consider turning off autodownload ( set sv_allowDownload to 0 ). Wolfenstein: Enemy Territory servers http/ftp download feature is not affected by CVE-2006-2082. If you don't wish to upgrade, you can decide to only enable http/ftp downloads and disable legacy downloads in that particular case.
There's also an updated Linux install file for RTCW, details at Timothee Besset's .plan. |