Vulnerabilities > CVE-2002-1245 - Unspecified vulnerability in Frank Mcingvale Luxman 0.41

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
frank-mcingvale
nessus

Summary

Maped in LuxMan 0.41 uses the user-provided search path to find and execute the gzip program, which allows local users to modify /dev/mem and gain privileges via a modified PATH environment variable that points to a Trojan horse gzip program.

Vulnerable Configurations

Part Description Count
Application
Frank_Mcingvale
1

Nessus

NASL familyDebian Local Security Checks
NASL idDEBIAN_DSA-189.NASL
descriptioniDEFENSE reported about a vulnerability in LuxMan, a maze game for GNU/Linux, similar to the PacMan arcade game. When successfully exploited a local attacker gains read-write access to the memory, leading to a local root compromise in many ways, examples of which include scanning the file for fragments of the master password file and modifying kernel memory to re-map system calls.
last seen2020-06-01
modified2020-06-02
plugin id15026
published2004-09-29
reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/15026
titleDebian DSA-189-1 : luxman - local root exploit