19984Third-party advisory
http://secunia.com/advisories/19984 CVE-2006-2236
Quake 3 Engine 1.32b - 'R_RemapShader()' Remote Client Buffer Overflow
Record summary
CVE-2006-2236 has a selected CVSS score of 7.6; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote attackers to execute arbitrary commands via a long remapShader command.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBQuake 3 Engine 1.32b - 'R_RemapShader()' Remote Client Buffer OverflowExploitDB exploitby landserNot analyzed1 file
References
1020065Third-party advisory
http://secunia.com/advisories/20065 GLSA-200605-12Vendor advisory
http://www.gentoo.org/security/en/glsa/glsa-200605-12.xml 25279vdb entry
http://www.osvdb.org/25279 20060508 Two independent vulnerabilities (client and server side) in Quake3 engine and many derived gamesmailing list
http://www.securityfocus.com/archive/1/433349/100/0/threaded 17857vdb entry
http://www.securityfocus.com/bid/17857 ADV-2006-1676vdb entry
http://www.vupen.com/english/advisories/2006/1676 quake3-remapshader-client-bo(26264)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/26264 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-2236 1750exploit
https://www.exploit-db.com/exploits/1750