CVE-2012-3345

ioquake3 before r2253 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ioq3.pid temporary file.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.6 UNKNOWN
LOCAL
HIGH
AV:L/AC:H/Au:N/C:N/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
VendorProductVersion
ioquake3ioquake3_engine
𝑥
≤ r2252
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ioquake3
bullseye
1.36+u20201117.d1b7ab6~dfsg-1
fixed
bookworm
1.36+u20221123.70d07d9+dfsg-1
fixed
trixie
1.36+u20240727.4c19ff2+dfsg-1
fixed
sid
1.36+u20241011.cc18246+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ioquake3
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
ignored
oneiric
ignored
natty
ignored
lucid
dne
hardy
dne