Vulnerability Name: | CVE-2006-1390 (CCN-25528) | ||||||||
Assigned: | 2006-03-23 | ||||||||
Published: | 2006-03-23 | ||||||||
Updated: | 2018-10-18 | ||||||||
Summary: | The configuration of NetHack 3.4.3-r1 and earlier, Falcon's Eye 1.9.4a and earlier, and Slash'EM 0.0.760 and earlier on Gentoo Linux allows local users in the games group to modify saved games files to execute arbitrary code via buffer overflows and overwrite arbitrary files via symlink attacks. This vulnerability applies only to the following games/versions: 1) NetHack 3.4.3-r1 and previous 2) Falcon's Eye 1.9.4a and previous 3) Slash'EM 0.0.760 and previous | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MISC Type: Exploit http://bugs.gentoo.org/show_bug.cgi?id=122376 Source: MISC Type: Exploit http://bugs.gentoo.org/show_bug.cgi?id=125902 Source: MISC Type: UNKNOWN http://bugs.gentoo.org/show_bug.cgi?id=127167 Source: MISC Type: UNKNOWN http://bugs.gentoo.org/show_bug.cgi?id=127319 Source: MITRE Type: CNA CVE-2006-1390 Source: CCN Type: SA19376 Gentoo nethack / falconseye / slashem Privilege Escalation Source: SECUNIA Type: Vendor Advisory 19376 Source: CCN Type: GLSA-200603-23 NetHack, Slash'EM, Falcon's Eye: Local privilege escalation Source: GENTOO Type: Patch GLSA-200603-23 Source: OSVDB Type: UNKNOWN 24104 Source: CCN Type: OSVDB ID: 24104 Gentoo Linux Multiple nethack Games High Score Processing Local Overflow Source: CCN Type: OSVDB ID: 24105 Gentoo Linux Multiple nethack Games Saved Game Symlink Arbitrary File Overwrite Source: BUGTRAQ Type: UNKNOWN 20060324 Re: [ GLSA 200603-23 ] NetHack, Slash'EM, Falcon's Eye: Localprivilege escalation Source: BUGTRAQ Type: UNKNOWN 20060324 Re: [ GLSA 200603-23 ] NetHack, Slash'EM, Falcon's Eye: Local privilege escalation Source: BID Type: UNKNOWN 17217 Source: CCN Type: BID-17217 Gentoo Nethack And Variants Local Privilege Escalation Vulnerability Source: XF Type: UNKNOWN gentoo-multiple-games-privilege-escalation(25528) Source: XF Type: UNKNOWN gentoo-multiple-games-privilege-escalation(25528) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |