Quake 2 server 3.13 on Linux does not properly check file...
Low severity
Unreviewed
Published
Apr 30, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Feb 25, 1998
Published to the GitHub Advisory Database
Apr 30, 2022
Last updated
Jan 30, 2023
Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file.
References