Title : Quake 3 Engine Remote Command Execution and Directory Traversal Vulnerabilities VUPEN ID : VUPEN/ADV-2006-1676 CVE ID : CVE-2006-2082 - CVE-2006-2236
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-05-05
Technical Description
Two vulnerabilities have been identified in Quake 3 Engine, which could be exploited by remote attackers to take complete control of an affected system or gain unauthorized access to arbitrary files.
The first flaw is due to a buffer overflow error when handling a specially crafted "remapShader" command, which could be exploited by remote attackers to execute arbitrary commands on a vulnerable client via a malicious server.
The second issue is due to an input validation error when handling ".pk3" file download requests, which could be exploited by attackers to download arbitrary files from a vulnerable server via directory traversal attacks.