4.6
CVSSv2

CVE-2004-0103

Published: 03/03/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

crawl prior to 4.0.0 beta23 does not properly "apply a size check" when copying a certain environment variable, which may allow local users to gain privileges, possibly as a result of a buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

linley henzell crawl

Vendor Advisories

Steve Kemp from the Debian Security Audit Project discovered a problem in crawl, another console based dungeon exploration game, in the vein of nethack and rogue The program uses several environment variables as inputs but doesn't apply a size check before copying one of them into a fixed size buffer For the stable distribution (woody) this probl ...