Gentoo Linux Security Advisory GLSA 200603-26
https://security.gentoo.org/
Severity: Normal
Title: bsd-games: Local privilege escalation in tetris-bsd
Date: March 29, 2006
Bugs: #122399
ID: 200603-26
Synopsis
=======
tetris-bsd is prone to local privilege escalation vulnerabilities.
Background
=========
bsd-games is a collection of NetBSD games ported to Linux.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 games-misc/bsd-games < 2.17-r1 >= 2.17-r1
==========
Tavis Ormandy of the Gentoo Linux Security Audit Team discovered that
the checkscores() function in scores.c reads in the data from the
/var/games/tetris-bsd.scores file without validation, renderin...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.