PT-1998-1237 · Id · Quake

Published

1998-04-08

·

Updated

2016-10-18

·

CVE-1999-1502

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Quake version 1.9
Description The issue concerns buffer overflows in the Quake 1.9 client, which can be exploited by remote malicious servers. This can lead to the execution of arbitrary commands via several means, including long precache paths, server name, server address, or arguments to the map console command.
Recommendations For Quake version 1.9, consider restricting access to untrusted servers and avoiding the use of long paths or arguments that could trigger the buffer overflow until a fix is available. As a temporary workaround, disabling the map console command or limiting its input could help minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1502

Affected Products

Quake