CVE-2019-15767

HIGH

GNU Chess 6.2.5 - Stack-based Buffer Overflow via EPD File

Title source: llm
STIX 2.1

Description

In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file.

References (5)

Core 5
Core References
Exploit, Mailing List, Third Party Advisory x_refsource_misc
https://lists.gnu.org/archive/html/bug-gnu-chess/2019-08/msg00004.html
Exploit, Mailing List, Third Party Advisory x_refsource_misc
https://lists.gnu.org/archive/html/bug-gnu-chess/2019-08/msg00005.html

Scores

CVSS v3 7.8
EPSS 0.0031
EPSS Percentile 53.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (1)
gnu/chess 6.2.5
Published Aug 29, 2019
Tracked Since Feb 18, 2026