Vulnerabilities > CVE-2004-0158 - Environment Variable Buffer Overflow Vulnerabilites in LGames LBreakout2

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
lgames
nessus
exploit available

Summary

Buffer overflow in lbreakout2 allows local users to gain 'games' group privileges via a large HOME environment variable to (1) editor.c, (2) theme.c, (3) manager.c, (4) config.c, (5) game.c, (6) levels.c, or (7) main.c.

Exploit-Db

descriptionLGames LBreakout2 2.2.2 Multiple Environment Variable Buffer Overflow Vulnerabilites. CVE-2004-0158. Local exploit for linux platform
idEDB-ID:23738
last seen2016-02-02
modified2004-02-21
published2004-02-21
reporterLi0n7
sourcehttps://www.exploit-db.com/download/23738/
titleLGames LBreakout2 2.2.2 - Multiple Environment Variable Buffer Overflow Vulnerabilites

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-445.NASL
    descriptionUlf Harnhammar from the Debian Security Audit Project discovered a vulnerability in lbreakout2, a game, where proper bounds checking was not performed on environment variables. This bug could be exploited by a local attacker to gain the privileges of group
    last seen2020-06-01
    modified2020-06-02
    plugin id15282
    published2004-09-29
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/15282
    titleDebian DSA-445-1 : lbreakout2 - buffer overflow
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_LBREAKOUT2_222_1.NASL
    descriptionThe following package needs to be updated: lbreakout2
    last seen2016-09-26
    modified2004-07-06
    plugin id12558
    published2004-07-06
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=12558
    titleFreeBSD : lbreakout2 vulnerability in environment variable handling (87)
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_AD4F6CA4672011D89FB5000A95BC6FAE.NASL
    descriptionUlf Harnhammar discovered an exploitable vulnerability in lbreakout2
    last seen2020-06-01
    modified2020-06-02
    plugin id37516
    published2009-04-23
    reporterThis script is Copyright (C) 2009-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/37516
    titleFreeBSD : lbreakout2 vulnerability in environment variable handling (ad4f6ca4-6720-11d8-9fb5-000a95bc6fae)