« Volver al listado

CVE-2006-3324

Estado: ModificadaMedia (5)—

The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attackers to overwrite arbitrary files in the quake3 directory (fs_homepath cvar) via a long string of filenames, as contained in the neededpaks buffer.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-3324",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-06-30T23:05:00.000",
  "references": [
    {
      "url": "http://aluigi.altervista.org/adv/q3cfilevar-adv.txt",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/20401",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/20851",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/1171",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://svn.icculus.org/quake3?rev=804&view=rev",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/438515/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/438660/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/18685",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/2569",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27486",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://aluigi.altervista.org/adv/q3cfilevar-adv.txt",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/20401",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/20851",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/1171",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://svn.icculus.org/quake3?rev=804&view=rev",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/438515/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/438660/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/18685",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/2569",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27486",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attackers to overwrite arbitrary files in the quake3 directory (fs_homepath cvar) via a long string of filenames, as contained in the neededpaks buffer."
    },
    {
      "lang": "es",
      "value": "la opción Automatic Downloading en id3 Quake v3 Engine y en Icculus Quake v3 Engine (ioquake3) anterior a la revisión 804 permite a atacantes remotos sobrescribir ficheros de su elección en el directorio quake3 (fs_homepath cvar) a través de cadenas de nombres de ficheros largas, tal y como figura en el búfer neededpaks."
    }
  ],
  "lastModified": "2026-06-16T22:26:50.663",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:id_software:quake_3_engine:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "68AE0171-46F1-4137-99BE-4B825A403D6E"
            },
            {
              "criteria": "cpe:2.3:a:id_software:quake_3_engine:1.32b:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FAC83733-F8B0-4985-BB48-2DA85C5C4393"
            },
            {
              "criteria": "cpe:2.3:a:id_software:quake_3_engine:1.32c:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "140AE21A-5028-485F-822C-4DA7F557A40C"
            },
            {
              "criteria": "cpe:2.3:a:id_software:quake_3_engine:icculus_803:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "875CD288-5C64-4396-8A2B-41B1309CE615"
            },
            {
              "criteria": "cpe:2.3:a:id_software:quake_3_engine:icculus_804:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B21AF67A-80EB-4596-882D-D184B73CAA0A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}