client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious servers to overwrite arbitrary write-protected cvars variables on the client, such as cl_allowdownload for Automatic Downloading and fs_homepath for the quake3 path, via a string of cvar names and values sent from the server.  NOTE: this can be combined with another vulnerability to overwrite arbitrary files.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2006-06-30 23:05
Updated : 2018-10-18 16:46
NVD link : CVE-2006-3325
Mitre link : CVE-2006-3325
CVE.ORG link : CVE-2006-3325
JSON object : View
Products Affected
                id_software
- quake_3_engine
 
CWE
                