Vulnerabilities > CVE-2004-2593 - Remote vulnerability in ID Software Quake II Server 3.20/3.21

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
id-software

Summary

Buffer overflow in command-packet processing of Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a packet with a long cmd_args buffer.

Vulnerable Configurations

Part Description Count
Application
Id_Software
2