CVE-2004-2592 describes a denial-of-service vulnerability affecting Quake II servers, specifically versions before R1Q2. A remote attacker can crash the server by sending a specially crafted client request that attempts to access data at a negative array offset during Configstring and Baseline processing. This vulnerability has a CVSS score of 5.0, indicating a medium severity, as it can be exploited remotely with low attack complexity, leading to an application crash without requiring authentication. While there is an ExploitDB entry referencing "Multiple Vulnerabilities" for Quake II, there is no specific exploit code for this CVE in Metasploit or Nuclei, and it is not listed in the CISA KEV catalog. Community discussion and media coverage for this vulnerability are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.20CPE matchmatch criteria | cpe:2.3:a:id_software:quake_ii_server:3.20:*:*:*:*:*:*:* | ||
3.21CPE matchmatch criteria | cpe:2.3:a:id_software:quake_ii_server:3.21:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.