Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/733 | vdb entry |
http://www.securityfocus.com/archive/1/8590 | mailing list exploit vendor advisory |