mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-01 11:01:35 +02:00
909 B
909 B
CVE-2006-3324
Description
The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attackers to overwrite arbitrary files in the quake3 directory (fs_homepath cvar) via a long string of filenames, as contained in the neededpaks buffer.
POC
Reference
- http://aluigi.altervista.org/adv/q3cfilevar-adv.txt
- http://aluigi.altervista.org/adv/q3cfilevar-adv.txt
- http://securityreason.com/securityalert/1171
- http://securityreason.com/securityalert/1171
Github
No PoCs found on GitHub currently.