CVE-2012-3345

EUVD-2012-3323
ioquake3 before r2253 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ioq3.pid temporary file.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.6 UNKNOWN
LOCAL
HIGH
AV:L/AC:H/Au:N/C:N/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
Affected Products (NVD)
VendorProductVersion
ioquake3ioquake3_engine
𝑥
≤ r2252
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ioquake3
bookworm
1.36+u20221123.70d07d9+dfsg-1
fixed
bullseye
1.36+u20201117.d1b7ab6~dfsg-1
fixed
sid
1.36+u20241011.cc18246+dfsg-1
fixed
trixie
1.36+u20240727.4c19ff2+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ioquake3
hardy
dne
lucid
dne
natty
ignored
oneiric
ignored
precise
ignored
quantal
not-affected
raring
not-affected
saucy
not-affected
trusty
dne
utopic
not-affected
vivid
not-affected
wily
not-affected
xenial
not-affected
yakkety
not-affected
zesty
not-affected