Vulnerabilities > CVE-2006-1539 - Unspecified vulnerability in Bsd-Games Tetris-Bsd Gold
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN bsd-games
nessus
Summary
Multiple buffer overflows in the checkscores function in scores.c in tetris-bsd in bsd-games before 2.17-r1 in Gentoo Linux might allow local users with games group membership to gain privileges by modifying tetris-bsd.scores to contain crafted executable content, which is executed when another user launches tetris-bsd.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-200603-26.NASL |
description | The remote host is affected by the vulnerability described in GLSA-200603-26 (bsd-games: Local privilege escalation in tetris-bsd) Tavis Ormandy of the Gentoo Linux Security Audit Team discovered that the checkscores() function in scores.c reads in the data from the /var/games/tetris-bsd.scores file without validation, rendering it vulnerable to buffer overflows and incompatible with the system used for managing games on Gentoo Linux. As a result, it cannot be played securely on systems with multiple users. Please note that this is probably a Gentoo-specific issue. Impact : A local user who is a member of group |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 21166 |
published | 2006-03-30 |
reporter | This script is Copyright (C) 2006-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/21166 |
title | GLSA-200603-26 : bsd-games: Local privilege escalation in tetris-bsd |
References
- http://bugs.gentoo.org/show_bug.cgi?id=122399
- http://bugs.gentoo.org/show_bug.cgi?id=122399
- http://secunia.com/advisories/19442
- http://secunia.com/advisories/19442
- http://www.gentoo.org/security/en/glsa/glsa-200603-26.xml
- http://www.gentoo.org/security/en/glsa/glsa-200603-26.xml
- http://www.osvdb.org/24261
- http://www.osvdb.org/24261
- http://www.securityfocus.com/bid/17308
- http://www.securityfocus.com/bid/17308
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25611
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25611