Vulnerabilities > CVE-2006-3324 - Unspecified vulnerability in ID Software Quake 3 Engine
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN id-software
exploit available
Summary
The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attackers to overwrite arbitrary files in the quake3 directory (fs_homepath cvar) via a long string of filenames, as contained in the neededpaks buffer.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |
Exploit-Db
description | Quake 3 Engine Client CG_ServerCommand() Remote Overflow Exploit. CVE-2006-3324,CVE-2006-3325,CVE-2006-3400. Dos exploit for windows platform |
file | exploits/windows/dos/1976.cpp |
id | EDB-ID:1976 |
last seen | 2016-01-31 |
modified | 2006-07-02 |
platform | windows |
port | |
published | 2006-07-02 |
reporter | RunningBon |
source | https://www.exploit-db.com/download/1976/ |
title | Quake 3 Engine Client CG_ServerCommand Remote Overflow Exploit |
type | dos |
References
- http://aluigi.altervista.org/adv/q3cfilevar-adv.txt
- http://aluigi.altervista.org/adv/q3cfilevar-adv.txt
- http://secunia.com/advisories/20401
- http://secunia.com/advisories/20401
- http://secunia.com/advisories/20851
- http://secunia.com/advisories/20851
- http://securityreason.com/securityalert/1171
- http://securityreason.com/securityalert/1171
- http://svn.icculus.org/quake3?rev=804&view=rev
- http://svn.icculus.org/quake3?rev=804&view=rev
- http://www.securityfocus.com/archive/1/438515/100/0/threaded
- http://www.securityfocus.com/archive/1/438515/100/0/threaded
- http://www.securityfocus.com/archive/1/438660/100/0/threaded
- http://www.securityfocus.com/archive/1/438660/100/0/threaded
- http://www.securityfocus.com/bid/18685
- http://www.securityfocus.com/bid/18685
- http://www.vupen.com/english/advisories/2006/2569
- http://www.vupen.com/english/advisories/2006/2569
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27486
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27486