Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Debian: 3.0 DSA 378-1 Critical: Mah-Jong Buffer Overflow, DoS Threats

debian
Calendar Grey September 8, 2003
Debian Logo
Upgrade Mah-Jong urgently due to critical buffer overflow and DoS vulnerabilities identified by Nicolas Boullis.
Nicolas Boullis discovered two vulnerabilities in mah-jong.

Summary

Nicolas Boullis discovered two vulnerabilities in mah-jong, a
network-enabled game.

- CAN-2003-0705 (buffer overflow)

This vulnerability could be exploited by a remote attacker to
execute arbitrary code with the privileges of the user running the
mah-jong server.

- - CAN-2003-0706 (denial of service)

This vulnerability could be exploited by a remote attacker to cause
the mah-jong server to enter a tight loop and stop responding to
commands.

For the stable distribution (woody) these problems have been fixed in
version 1.4-2.

For the unstable distribution (sid) these problems have been fixed in
version 1.5.6-2.

We recommend that you update your mah-jong package.

Upgrade Instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corr...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: mah-jong

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here