CVE-2006-1390
Summary
| CVE | CVE-2006-1390 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-03-25 00:06:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The configuration of NetHack 3.4.3-r1 and earlier, Falcon's Eye 1.9.4a and earlier, and Slash'EM 0.0.760 and earlier on Gentoo Linux allows local users in the games group to modify saved games files to execute arbitrary code via buffer overflows and overwrite arbitrary files via symlink attacks. |
Risk And Classification
Primary CVSS: v2.0 4.6 from [email protected]
AV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS: 0.002190000 probability, percentile 0.445720000 (date 2026-04-19)
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Gentoo | Linux | 0.5 | All | All | All |
| Operating System | Gentoo | Linux | 0.7 | All | All | All |
| Operating System | Gentoo | Linux | 1.1a | All | All | All |
| Operating System | Gentoo | Linux | 1.2 | All | All | All |
| Operating System | Gentoo | Linux | 1.4 | All | All | All |
| Operating System | Gentoo | Linux | 1.4 | rc1 | All | All |
| Operating System | Gentoo | Linux | 1.4 | rc2 | All | All |
| Operating System | Gentoo | Linux | 1.4 | rc3 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Gentoo Linux Documentation -- NetHack, Slash'EM, Falcon's Eye: Local privilege escalation | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | Patch |
| 122376 – games-roguelike/nethack: insecure save game creation | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | Exploit |
| 127319 – games-roguelike/falconseye: local privilege escalation | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | |
| Gentoo Bug 125902 - games-roguelike/nethack: local privilege escalation and insecure savegame creation (CVE-2006-1390) | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | Exploit |
| Gentoo Nethack And Variants Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 127167 – games-roguelike/slashem: insecure save game creation and local priv escalation(CVE-2006-1390) | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| www.osvdb.org/24104 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Gentoo nethack / falconseye / slashem Privilege Escalation - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.