EIP-2026-118627
PRE-CVEHalf-Life 1.1 - Invalid Command Error Response Format String
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118627. PoCs published by Luigi Auriemma.
AI-analyzed exploit summary The entry describes a format string vulnerability in Half-Life clients where an invalid command with format specifiers triggers arbitrary code execution when the error response is displayed. The vulnerability stems from improper handling of user-controlled input in error messages.
Description
Half-Life 1.1 - Invalid Command Error Response Format String
Exploits (1)
The entry describes a format string vulnerability in Half-Life clients where an invalid command with format specifiers triggers arbitrary code execution when the error response is displayed. The vulnerability stems from improper handling of user-controlled input in error messages.