4.6
CVSSv2

CVE-2005-0105

Published: 16/02/2005 Updated: 05/09/2008
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unknown vulnerability in typespeed 0.4.1 and previous versions allows local users to gain privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

typespeed typespeed 0.4.1

Vendor Advisories

Ulf Härnhammar from the Debian Security Audit Project discovered a problem in typespeed, a touch-typist trainer disguised as game This could lead to a local attacker executing arbitrary code as group games For the stable distribution (woody) this problem has been fixed in version 041-23 For the unstable distribution (sid) this problem will b ...

Exploits

source: wwwsecurityfocuscom/bid/12569/info typespeed is prone to a local format string vulnerability Successful could allow privilege escalation /* Proof of Concept local exploit for typespeed tool "enva" content: ********************************************* #include <stdioh> #include <stringh> int main(int argc, c ...