client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious servers to overwrite arbitrary write-protected cvars variables on the client, such as cl_allowdownload for Automatic Downloading and fs_homepath for the quake3 path, via a string of cvar names and values sent from the server. NOTE: this can be combined with another vulnerability to overwrite arbitrary files.
2006-06-30T23:05:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | id_software | quake_3_engine | * | Yes |
Application | id_software | quake_3_engine | 1.32b | Yes |
Application | id_software | quake_3_engine | 1.32c | Yes |
Application | id_software | quake_3_engine | icculus_803 | Yes |
Application | id_software | quake_3_engine | icculus_804 | Yes |
Application | id_software | quake_3_engine | icculus_805 | Yes |
Application | id_software | quake_3_engine | icculus_806 | Yes |
Application | id_software | quake_3_engine | icculus_807 | Yes |
Application | id_software | quake_3_engine | icculus_808 | Yes |
Application | id_software | quake_3_engine | icculus_809 | Yes |
Application | id_software | quake_3_engine | icculus_810 | Yes |