PT-2005-1228 · Golddig · Golddig
Publicado
2005-01-19
·
Atualizado
2017-07-11
·
CVE-2005-0121
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
golddig versions 2.0 and earlier
Description
The issue concerns buffer overflows that allow local users to execute arbitrary code. This can be achieved via a long map name command line argument or a long username as recorded in the
USER environment variable.Recommendations
For versions 2.0 and earlier, consider updating to a version that is not affected by this issue, if available. As a temporary workaround, restrict the length of map names and usernames to prevent exploitation. Avoid using long map names as command line arguments and limit the length of usernames recorded in the
USER environment variable until a fix is applied.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Golddig