CVE-2012-3345: Medium severity ioquake3 ioQuake3 engine vulnerability
Published Jun 15, 2012
·Updated
ioquake3 before r2253 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ioq3.pid temporary file.
Affected Software
1 affected component
ioquake3 ioQuake3 engine<=r2252
Event History
Jun 15, 2012
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3345?
CVE-2012-3345 has a medium severity rating due to its potential for local users to exploit the vulnerability for unauthorized file access.
2
How do I fix CVE-2012-3345?
To fix CVE-2012-3345, users should upgrade to ioquake3 version r2253 or later, which addresses the symlink attack issue.
3
Who is affected by CVE-2012-3345?
CVE-2012-3345 affects local users of ioquake3 versions prior to r2253, allowing them to perform symlink attacks.
4
What is the impact of exploiting CVE-2012-3345?
Exploiting CVE-2012-3345 can allow local users to overwrite arbitrary files, potentially compromising system integrity.
5
Is CVE-2012-3345 still a concern for current software?
CVE-2012-3345 is not a concern for current software versions, as it has been addressed in updates since r2253.