PT-2005-1228 · Golddig · Golddig
Published
2005-01-19
·
Updated
2017-07-11
·
CVE-2005-0121
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
golddig versions 2.0 and earlier
Description
The issue concerns buffer overflows that allow local users to execute arbitrary code. This can be achieved via a long map name command line argument or a long username as recorded in the
USER environment variable.Recommendations
For versions 2.0 and earlier, consider updating to a version that is not affected by this issue, if available. As a temporary workaround, restrict the length of map names and usernames to prevent exploitation. Avoid using long map names as command line arguments and limit the length of usernames recorded in the
USER environment variable until a fix is applied.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Golddig