First published: Fri Jun 15 2012(Updated: )
ioquake3 before r2253 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ioq3.pid temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ioQuake3 | <=r2252 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3345 has a medium severity rating due to its potential for local users to exploit the vulnerability for unauthorized file access.
To fix CVE-2012-3345, users should upgrade to ioquake3 version r2253 or later, which addresses the symlink attack issue.
CVE-2012-3345 affects local users of ioquake3 versions prior to r2253, allowing them to perform symlink attacks.
Exploiting CVE-2012-3345 can allow local users to overwrite arbitrary files, potentially compromising system integrity.
CVE-2012-3345 is not a concern for current software versions, as it has been addressed in updates since r2253.