Vulnerabilities > CVE-1999-1229 - Unspecified vulnerability in ID Software Quake 2 Server

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
low complexity
id-software

Summary

Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file.

Vulnerable Configurations

Part Description Count
Application
Id_Software
1