Vulnerabilities > CVE-2006-2196 - Local Security vulnerability in Jochen Friedrich Pinball 0.3.1

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
jochen-friedrich
nessus

Summary

Unspecified vulnerability in pinball 0.3.1 allows local users to gain privileges via unknown attack vectors that cause pinball to load plugins from an attacker-controlled directory while operating at raised privileges.

Vulnerable Configurations

Part Description Count
Application
Jochen_Friedrich
1

Nessus

NASL familyDebian Local Security Checks
NASL idDEBIAN_DSA-1102.NASL
descriptionSteve Kemp from the Debian Security Audit project discovered that pinball, a pinball simulator, can be tricked into loading level plugins from user-controlled directories without dropping privileges.
last seen2020-06-01
modified2020-06-02
plugin id22644
published2006-10-14
reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/22644
titleDebian DSA-1102-1 : pinball - design error