romload.c in DGen Emulator 1.23 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files during decompression of (1) gzip or (2) bzip ROM files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Emulator | Dgen | 1.15 (including) | 1.15 (including) |
Emulator | Dgen | 1.16 (including) | 1.16 (including) |
Emulator | Dgen | 1.17 (including) | 1.17 (including) |
Emulator | Dgen | 1.18 (including) | 1.18 (including) |
Emulator | Dgen | 1.20 (including) | 1.20 (including) |
Emulator | Dgen | 1.20_a (including) | 1.20_a (including) |
Emulator | Dgen | 1.21 (including) | 1.21 (including) |
Emulator | Dgen | 1.22 (including) | 1.22 (including) |
Emulator | Dgen | 1.23 (including) | 1.23 (including) |