Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file.
References
Link | Resource |
---|---|
http://www.securityfocus.com/archive/1/8590 | Exploit Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/733 |
Configurations
Information
Published : 1998-02-24 21:00
Updated : 2017-12-18 18:29
NVD link : CVE-1999-1229
Mitre link : CVE-1999-1229
JSON object : View
CWE
Products Affected
id_software
- quake_2_server