4.6
CVSSv2

CVE-2006-2196

Published: 26/06/2006 Updated: 20/07/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unspecified vulnerability in pinball 0.3.1 allows local users to gain privileges via unknown attack vectors that cause pinball to load plugins from an attacker-controlled directory while operating at raised privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

jochen friedrich pinball 0.3.1

Vendor Advisories

Steve Kemp from the Debian Security Audit project discovered that pinball, a pinball simulator, can be tricked into loading level plugins from user-controlled directories without dropping privileges The old stable distribution (woody) does not contain this package For the stable distribution (sarge) this problem has been fixed in version 031-3s ...