Quake Console Command Buffer Overflow Vulnerability
BID:69
Info
Quake Console Command Buffer Overflow Vulnerability
| Bugtraq ID: | 69 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-1999-1502 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 08 1998 12:00AM |
| Updated: | Jul 11 2009 12:16AM |
| Credit: | This vulnerability was published as "QuakeI client: serious holes." by Chris Evans <[email protected]> in the BugTraq mailing list on April 8, 1998. |
| Vulnerable: |
id Software Quake 1.9 |
| Not Vulnerable: | |
Discussion
Quake Console Command Buffer Overflow Vulnerability
As part of the Quake protocol the server can give the client arbitrary console commands. Of these at least "map string_longer_than_64_characters" will cause a buffer overflow in the stack.
As part of the Quake protocol the server can give the client arbitrary console commands. Of these at least "map string_longer_than_64_characters" will cause a buffer overflow in the stack.
Exploit / POC
Quake Console Command Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Quake Console Command Buffer Overflow Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Quake Console Command Buffer Overflow Vulnerability
References:
References: