PT-2002-2176 · Freebsd+1 · Freebsd+1
Published
2002-10-15
·
Updated
2017-07-11
·
CVE-2002-1192
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
NetBSD versions 1.6 and earlier
FreeBSD version 4.6
Description:
The issue is related to multiple buffer overflows in the rogue game, which can be exploited by local users to gain "games" group privileges. This is achieved through the use of malformed entries in a game save file.
Recommendations:
For NetBSD versions 1.6 and earlier, consider restricting access to the rogue game until a fix is available.
For FreeBSD version 4.6, avoid using the rogue game with untrusted save files until the issue is resolved.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freebsd
Netbsd