PT-2006-3172 · Pinball · Pinball

Published

2006-06-26

·

Updated

2017-07-20

·

CVE-2006-2196

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions pinball version 0.3.1
Description The issue allows local users to gain privileges through unknown attack vectors, causing pinball to load plugins from an attacker-controlled directory while operating at raised privileges.
Recommendations For pinball version 0.3.1, consider restricting the loading of plugins to only trusted directories until a fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2196
DSA-1102

Affected Products

Pinball