PT-2002-2176 · Freebsd+1 · Freebsd+1

Published

2002-10-15

·

Updated

2017-07-11

·

CVE-2002-1192

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: NetBSD versions 1.6 and earlier FreeBSD version 4.6
Description: The issue is related to multiple buffer overflows in the rogue game, which can be exploited by local users to gain "games" group privileges. This is achieved through the use of malformed entries in a game save file.
Recommendations: For NetBSD versions 1.6 and earlier, consider restricting access to the rogue game until a fix is available. For FreeBSD version 4.6, avoid using the rogue game with untrusted save files until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1192

Affected Products

Freebsd
Netbsd