PT-2003-1033 · Debian · Xgalaga
Published
2003-07-04
·
Updated
2008-09-05
·
CVE-2003-0454
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
xgalaga versions 2.0.34 and earlier
Description
The issue concerns multiple vulnerabilities in the xgalaga package of the Debian GNU/Linux operating system, which can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. A key aspect of this issue is the presence of multiple buffer overflows, specifically in versions 2.0.34 and earlier, which can be triggered by a local user setting a long
HOME environment variable.Recommendations
For xgalaga versions 2.0.34 and earlier, consider restricting access to the
HOME environment variable to prevent exploitation of the buffer overflow vulnerability until a patch is available.
As a temporary workaround, avoid using long values for the HOME environment variable in affected versions of xgalaga.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xgalaga