Buffer overflow in pl_main.c in sail in BSDgames before 2.17-7 allows local users to execute arbitrary code via a long player name that is used in a scanf function call.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Bsdgames | Joey_hess | 2.9 (including) | 2.9 (including) |
| Bsdgames | Joey_hess | 2.12 (including) | 2.12 (including) |
| Bsdgames | Joey_hess | 2.13 (including) | 2.13 (including) |
| Bsdgames | Joey_hess | 2.14 (including) | 2.14 (including) |
| Bsdgames | Joey_hess | 2.17 (including) | 2.17 (including) |