CVE-2006-3325

id3 Quake 3 Engine <1.32c - RCE

Title source: llm

Description

client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious servers to overwrite arbitrary write-protected cvars variables on the client, such as cl_allowdownload for Automatic Downloading and fs_homepath for the quake3 path, via a string of cvar names and values sent from the server. NOTE: this can be combined with another vulnerability to overwrite arbitrary files.

Exploits (2)

exploitdb WORKING POC
cppdoswindows_x86
https://www.exploit-db.com/exploits/1977
exploitdb WORKING POC
cppdoswindows
https://www.exploit-db.com/exploits/1976

Scores

EPSS 0.0393
EPSS Percentile 88.1%

Classification

Status draft

Affected Products (11)

id_software/quake_3_engine
id_software/quake_3_engine
id_software/quake_3_engine
id_software/quake_3_engine
id_software/quake_3_engine
id_software/quake_3_engine
id_software/quake_3_engine
id_software/quake_3_engine
id_software/quake_3_engine
id_software/quake_3_engine
id_software/quake_3_engine

Timeline

Published Jun 30, 2006
Tracked Since Feb 18, 2026