VYPR
Unrated severityNVD Advisory· Published Jun 30, 2006· Updated Apr 16, 2026

CVE-2006-3325

CVE-2006-3325

Description

client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious servers to overwrite arbitrary write-protected cvars variables on the client, such as cl_allowdownload for Automatic Downloading and fs_homepath for the quake3 path, via a string of cvar names and values sent from the server. NOTE: this can be combined with another vulnerability to overwrite arbitrary files.

Affected products

11
  • cpe:2.3:a:id_software:quake_3_engine:*:*:*:*:*:*:*:*+ 10 more
    • cpe:2.3:a:id_software:quake_3_engine:*:*:*:*:*:*:*:*
    • cpe:2.3:a:id_software:quake_3_engine:1.32b:*:*:*:*:*:*:*
    • cpe:2.3:a:id_software:quake_3_engine:1.32c:*:*:*:*:*:*:*
    • cpe:2.3:a:id_software:quake_3_engine:icculus_803:*:*:*:*:*:*:*
    • cpe:2.3:a:id_software:quake_3_engine:icculus_804:*:*:*:*:*:*:*
    • cpe:2.3:a:id_software:quake_3_engine:icculus_805:*:*:*:*:*:*:*
    • cpe:2.3:a:id_software:quake_3_engine:icculus_806:*:*:*:*:*:*:*
    • cpe:2.3:a:id_software:quake_3_engine:icculus_807:*:*:*:*:*:*:*
    • cpe:2.3:a:id_software:quake_3_engine:icculus_808:*:*:*:*:*:*:*
    • cpe:2.3:a:id_software:quake_3_engine:icculus_809:*:*:*:*:*:*:*
    • cpe:2.3:a:id_software:quake_3_engine:icculus_810:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.