CVE-2001-1289 is a denial-of-service vulnerability affecting id Software Quake 3 Arena versions 1.29f and 1.29g. Remote attackers can crash the game server by sending a malformed connection packet containing multiple char-255 characters. Rated Medium severity (CVSS 5.0), it requires no authentication and has low attack complexity, leading to a potential loss of availability. While not listed on CISA's KEV catalog, an ExploitDB entry exists for a buffer overflow, and the vulnerability has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.29fCPE matchmatch criteria | cpe:2.3:a:id_software:quake_3_arena:1.29f:*:*:*:*:*:*:* | ||
1.29gCPE matchmatch criteria | cpe:2.3:a:id_software:quake_3_arena:1.29g:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.