Quake 3 Multiple Vulnerabilities
BID:18685
CVE-2006-3324 | CVE-2006-3325 |Info
Quake 3 Multiple Vulnerabilities
| Bugtraq ID: | 18685 |
| Class: | Unknown |
| CVE: |
CVE-2006-3324 CVE-2006-3325 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2006 12:00AM |
| Updated: | May 07 2015 05:03PM |
| Credit: | Luigi Auriemma is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
id Software Quake 3 Engine (Icculus Version) 804 id Software Quake 3 Engine (Icculus Version) 803 id Software Quake 3 Engine 1.32 c id Software Quake 3 Engine 1.32 b |
| Not Vulnerable: | |
Discussion
Quake 3 Multiple Vulnerabilities
Quake 3 is prone to vulnerabilities that may allow attackers to access and steal privileged data. These issues are due to a design error and to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to overwrite other game player files with arbitrary data and to gain access to potentially sensitive information. This will result in a loss of data and possibly a loss of confidentiality.
Quake 3 is prone to vulnerabilities that may allow attackers to access and steal privileged data. These issues are due to a design error and to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to overwrite other game player files with arbitrary data and to gain access to potentially sensitive information. This will result in a loss of data and possibly a loss of confidentiality.
Exploit / POC
Quake 3 Multiple Vulnerabilities
Attackers can exploit this issue with a modified version of the Quake source code.
A sample patch file to demonstrate this vulnerability has been provided:
Attackers can exploit this issue with a modified version of the Quake source code.
A sample patch file to demonstrate this vulnerability has been provided:
Solution / Fix
Quake 3 Multiple Vulnerabilities
Solution:
The vendor has fixed the "Automatic Downloading" vulnerability in Icculus Quake 3 Version 803; please see the reference section for details.
Solution:
The vendor has fixed the "Automatic Downloading" vulnerability in Icculus Quake 3 Version 803; please see the reference section for details.
References
Quake 3 Multiple Vulnerabilities
References:
References:
- icculus.org/quake3 Home Page (icculus.org)
- id Software Home Page (id Software)
- Files and cvars overwriting in Quake 3 engine (1.32c / rev 803 / ...) (Luigi Auriemma
) - Re: Files and cvars overwriting in Quake 3 engine (1.32c / rev 803/ ...) (Luigi Auriemma
)