BSD-Games Multiple Local Buffer Overflow Vulnerabilities

Bleh, just a crappy bug i’ve found a few years ago.

BSD-Games Multiple Local Buffer Overflow Vulnerabilities

Multiple games in the BSD-games package are prone to locally exploitable buffer-overflow vulnerabilities. These issues are due to insufficient bounds-checking when copying user-supplied input to insufficiently sized memory buffers.

Since these games are installed ‘setgid games’ on many operating systems, attackers may be able to exploit these issues to escalate privileges to this level.

~ by aLS -- on January 11, 2007.

