Secunia Security Advisory - Tavis Ormandy has reported some vulnerabilities in the bsd-games package, which potentially can be exploited by malicious, local users to gain escalated privileges.
9ecf38090a65c4713e63647729a1d339bf2a486ff41cac43bdbf0a1919e230d8
TITLE:
Gentoo bsd-games Privilege Escalation Vulnerability
SECUNIA ADVISORY ID:
SA19442
VERIFY ADVISORY:
http://secunia.com/advisories/19442/
CRITICAL:
Less critical
IMPACT:
Privilege escalation
WHERE:
Local system
OPERATING SYSTEM:
Gentoo Linux 1.x
http://secunia.com/product/339/
DESCRIPTION:
Tavis Ormandy has reported some vulnerabilities in the bsd-games
package, which potentially can be exploited by malicious, local users
to gain escalated privileges.
The vulnerabilities are caused due to boundary errors when reading
the player's name and level information from the
"/var/games/tetris-bsd.scores" file. This can be exploited by users
in the "games" group to cause a stack-based buffer overflow when
other users run the game, by modifying entries in the file.
Successful exploitation allows the execution of arbitrary code with
the privileges of other users.
SOLUTION:
Update to "games-misc/bsd-games-2.17-r1" or later.
PROVIDED AND/OR DISCOVERED BY:
Tavis Ormandy, Gentoo Linux Security Audit Team.
ORIGINAL ADVISORY:
http://www.gentoo.org/security/en/glsa/glsa-200603-26.xml
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------