CVE Vulnerabilities

CVE-2006-1390

Published: Mar 25, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The configuration of NetHack 3.4.3-r1 and earlier, Falcons Eye 1.9.4a and earlier, and SlashEM 0.0.760 and earlier on Gentoo Linux allows local users in the games group to modify saved games files to execute arbitrary code via buffer overflows and overwrite arbitrary files via symlink attacks.

Affected Software

Name Vendor Start Version End Version
Linux Gentoo 0.5 (including) 0.5 (including)
Linux Gentoo 0.7 (including) 0.7 (including)
Linux Gentoo 1.1a (including) 1.1a (including)
Linux Gentoo 1.2 (including) 1.2 (including)
Linux Gentoo 1.4 (including) 1.4 (including)
Linux Gentoo 1.4-rc1 (including) 1.4-rc1 (including)
Linux Gentoo 1.4-rc2 (including) 1.4-rc2 (including)
Linux Gentoo 1.4-rc3 (including) 1.4-rc3 (including)

References