7.2
CVSSv2

CVE-2003-0454

Published: 07/08/2003 Updated: 05/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple buffer overflows in xgalaga 2.0.34 and previous versions allow local users to gain privileges via a long HOME environment variable.

Vulnerable Product Search on Vulmon Subscribe to Product

joe rumsey xgalaga 2.0.34

Vendor Advisories

Steve Kemp discovered several buffer overflows in xgalaga, a game, which can be triggered by a long HOME environment variable This vulnerability could be exploited by a local attacker to gain gid 'games' For the stable distribution (woody) this problem has been fixed in version 2034-19woody1 For the unstable distribution (sid) this problem is ...

Exploits

/* 0x333xgalaga => XGalaga 2034 local game exploit (Red Hat 90) * * tested against xgalaga-2034-1i386rpm * under Red Hat Linux 90 * * - bug found by Steve Kemp * - exploit coded by c0wboy @ 0x333 * * (c) 0x333 Outsider Security Labs / www0x333org * */ #include <stdioh> #include <stringh> #include <unistdh> #def ...