The configuration of NetHack 3.4.3-r1 and earlier, Falcon's Eye 1.9.4a...
Vulnerability Description
The configuration of NetHack 3.4.3-r1 and earlier, Falcon's Eye 1.9.4a and earlier, and Slash'EM 0.0.760 and earlier on Gentoo Linux allows local users in the games group to modify saved games files to execute arbitrary code via buffer overflows and overwrite arbitrary files via symlink attacks.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-1390
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/19376
- http://www.gentoo.org/security/en/glsa/glsa-200603-23.xml
- http://bugs.gentoo.org/show_bug.cgi?id=125902
- http://bugs.gentoo.org/show_bug.cgi?id=127167
- http://bugs.gentoo.org/show_bug.cgi?id=127319
- http://www.securityfocus.com/archive/1/428739/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25528
- http://www.securityfocus.com/archive/1/428743/100/0/threaded
- http://bugs.gentoo.org/show_bug.cgi?id=122376
- http://www.osvdb.org/24104
- http://www.securityfocus.com/bid/17217
More from gentoo
View All →Affected Vendor
gentoo
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.