|
|
Info |
Last Modified |
| 6 months ago |
|
|
|
|
Description |
A local overflow exists in Nethack, Falsconseye, and Slashem. Gentoo's group game policy allows users to manipulate the game's record and state files. Nethack, Falsconseye, and Slashem fail to properly check record data in '/var/games/nethack/record' resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code execution with the rights of other players resulting in a loss of integrity.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
Gentoo Linux
 |
1.4 _rc3 |
1.4 _rc2 |
1.4 _rc1 |
1.4 |
1.2 |
1.1 a |
0.7 |
0.5 |
|
|
|
|
|
Credit |
- Tavis Ormandy - taviso
google.com - Google Information Security Team
- Raymond Lewis Rebbeck -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|