CVE
- Id
- 11023
- CVE No.
- CVE-2004-2597
- Status
- Candidate
- Description
- Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo string that already contains an "ip" key/value pair but is also long enough to cause a new key/value pair to be truncated, which interferes with the server"s ability to find the client"s IP address.
- Phase
- Assigned (20051129)
- Votes
- None (candidate not yet proposed)
- Comments