20040222 lbreakout2 < 2.4beta-2 local exploitmailing list
http://marc.info/?l=bugtraq&m=107755821705356&w=2 CVE-2004-0158
LGames LBreakout2 2.2.2 - Multiple Environment Variable Buffer Overflow Vulnerabilities
Record summary
CVE-2004-0158 has a selected CVSS score of 4.6; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in lbreakout2 allows local users to gain 'games' group privileges via a large HOME environment variable to (1) editor.c, (2) theme.c, (3) manager.c, (4) config.c, (5) game.c, (6) levels.c, or (7) main.c.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBLGames LBreakout2 2.2.2 - Multiple Environment Variable Buffer Overflow VulnerabilitiesExploitDB exploitby Li0n7Not analyzed1 file
References
6security.debian.orgConfirmation
http://security.debian.org/pool/updates/main/l/lbreakout2/lbreakout2_2.2.2-1woody1.diff.gz DSA-445Vendor advisory
http://www.debian.org/security/2004/dsa-445 9712vdb entry
http://www.securityfocus.com/bid/9712 breakout2-home-bo(15229)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/15229 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-0158