CVE-2006-3325 - CVE House
Back to Database
Status published Medium CVE-2006-3325

client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the...

Vulnerability Description

client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious servers to overwrite arbitrary write-protected cvars variables on the client, such as cl_allowdownload for Automatic Downloading and fs_homepath for the quake3 path, via a string of cvar names and values sent from the server. NOTE: this can be combined with another vulnerability to overwrite arbitrary files.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-3325

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

id software

View all reports →

Affected Software

quake 3 engine
Vulnerable Versions:
1.32b, 1.32c, icculus_803, icculus_804, icculus_805, icculus_806, icculus_807, icculus_808, icculus_809, icculus_810

Timeline

Official Publish: June 30th, 2006
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.