PT-2006-4218 · Id+1 · Id3 Quake 3 Engine+1
Luigi Auriemma
·
Published
2006-06-30
·
Updated
2018-10-18
·
CVE-2006-3325
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
id3 Quake 3 Engine version 1.32c
ioquake3 revision 810 and earlier
Description
The issue allows remote malicious servers to overwrite arbitrary write-protected cvars variables on the client, such as
cl allowdownload for Automatic Downloading and fs homepath for the quake3 path, via a string of cvar names and values sent from the server.Recommendations
For id3 Quake 3 Engine version 1.32c, consider disabling the
cl parse.c file functionality until a patch is available.
For ioquake3 revision 810 and earlier, restrict access to the vulnerable cvar variables, such as cl allowdownload and fs homepath, to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Id3 Quake 3 Engine
Ioquake3