PT-2003-2391 · Rogue · Rogue

Published

2003-12-31

·

Updated

2017-07-29

·

CVE-2003-1446

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Rogue version 5.2-2
Description The issue is related to a buffer overflow in the save into file function, located in the save.c file. This allows local users to execute arbitrary code with games group privileges. The exploitation is possible by setting a long HOME environment variable and invoking the save game function with a ~ (tilde).
Recommendations For Rogue version 5.2-2, consider restricting access to the save into file function in save.c until a patch is available. As a temporary workaround, avoid using the save game function with a ~ (tilde) when the HOME environment variable is set to a long value.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2003-1446

Affected Products

Rogue