PT-2006-4218 · Id+1 · Id3 Quake 3 Engine+1

Luigi Auriemma

·

Published

2006-06-30

·

Updated

2018-10-18

·

CVE-2006-3325

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions id3 Quake 3 Engine version 1.32c ioquake3 revision 810 and earlier
Description The issue allows remote malicious servers to overwrite arbitrary write-protected cvars variables on the client, such as cl allowdownload for Automatic Downloading and fs homepath for the quake3 path, via a string of cvar names and values sent from the server.
Recommendations For id3 Quake 3 Engine version 1.32c, consider disabling the cl parse.c file functionality until a patch is available. For ioquake3 revision 810 and earlier, restrict access to the vulnerable cvar variables, such as cl allowdownload and fs homepath, to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3325

Affected Products

Id3 Quake 3 Engine
Ioquake3