Vulnerabilities > CVE-2006-3400 - Stack Buffer Overflow vulnerability in Quake 3 Engine Client

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
id-software
raven-software
exploit available

Summary

Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remote attackers to cause a denial of service and possibly execute code by sending a long command from the server.

Exploit-Db

descriptionQuake 3 Engine Client CG_ServerCommand() Remote Overflow Exploit. CVE-2006-3324,CVE-2006-3325,CVE-2006-3400. Dos exploit for windows platform
fileexploits/windows/dos/1976.cpp
idEDB-ID:1976
last seen2016-01-31
modified2006-07-02
platformwindows
port
published2006-07-02
reporterRunningBon
sourcehttps://www.exploit-db.com/download/1976/
titleQuake 3 Engine Client CG_ServerCommand Remote Overflow Exploit
typedos