CVE-2006-2236

Quake 3 Engine - Buffer Overflow via Long remapShader Command

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-2236. PoCs published by landser.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in the Quake 3 engine (CVE-2006-2236) by hooking server functions to send malformed 'remapShader' commands to clients, resulting in remote code execution. The shellcode binds a shell on a specified port and exits cleanly with an error message.

Description

Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote attackers to execute arbitrary commands via a long remapShader command.

Exploits (1)

exploitdb WORKING POC VERIFIED
by landser · cremotelinux
https://www.exploit-db.com/exploits/1750

This exploit targets a buffer overflow vulnerability in the Quake 3 engine (CVE-2006-2236) by hooking server functions to send malformed 'remapShader' commands to clients, resulting in remote code execution. The shellcode binds a shell on a specified port and exits cleanly with an error message.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Quake 3 Engine 1.32b (ET 2.60, RtCW 1.41, Q3 1.32b)
No auth needed
Prerequisites: Server with LD_PRELOAD capability · Vulnerable client connecting to the server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/433349/100/0/threaded
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19984
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1676
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17857
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200605-12.xml
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20065
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/26264
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/1750
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/25279

Scores

EPSS 0.0759
EPSS Percentile 93.8%

Details

Status published
Products (4)
id_software/quake_3_arena 1.32b
id_software/quake_3_engine 1.32b
id_software/return_to_castle_wolfenstein 1.41
id_software/wolfenstein_enemy_territory 2.60
Published May 08, 2006
Tracked Since Feb 18, 2026