{"api_version":"1","generated_at":"2026-07-23T08:32:27+00:00","cve":"CVE-2002-0125","urls":{"html":"https://cve.report/CVE-2002-0125","api":"https://cve.report/api/cve/CVE-2002-0125.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0125","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0125"},"summary":{"title":"CVE-2002-0125","description":"Buffer overflow in ClanLib library 0.5 may allow local users to execute arbitrary code in games that use the library, such as (1) Super Methane Brothers, (2) Star War, (3) Kwirk, (4) Clankanoid, and others, via a long HOME environment variable.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-03-25 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/3877","name":"http://www.securityfocus.com/bid/3877","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ClanLib Environment Variable Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://online.securityfocus.com/archive/1/250414","name":"http://online.securityfocus.com/archive/1/250414","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SecurityFocus","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/7905.php","name":"http://www.iss.net/security_center/static/7905.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"ISS X-Force Database: clanlib-long-env-bo (7905): ClanLib long environment variable buffer overflow","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0125","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0125","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"125","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"clanlib","cpe5":"clanlib","cpe6":"0.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:35:17.531Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"3877","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/3877"},{"name":"20020114 Clanlib overflow / Super Methane Brothers overflow","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://online.securityfocus.com/archive/1/250414"},{"name":"clanlib-long-env-bo(7905)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/7905.php"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-01-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Buffer overflow in ClanLib library 0.5 may allow local users to execute arbitrary code in games that use the library, such as (1) Super Methane Brothers, (2) Star War, (3) Kwirk, (4) Clankanoid, and others, via a long HOME environment variable."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2002-03-22T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"3877","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/3877"},{"name":"20020114 Clanlib overflow / Super Methane Brothers overflow","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://online.securityfocus.com/archive/1/250414"},{"name":"clanlib-long-env-bo(7905)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/7905.php"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0125","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Buffer overflow in ClanLib library 0.5 may allow local users to execute arbitrary code in games that use the library, such as (1) Super Methane Brothers, (2) Star War, (3) Kwirk, (4) Clankanoid, and others, via a long HOME environment variable."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"3877","refsource":"BID","url":"http://www.securityfocus.com/bid/3877"},{"name":"20020114 Clanlib overflow / Super Methane Brothers overflow","refsource":"BUGTRAQ","url":"http://online.securityfocus.com/archive/1/250414"},{"name":"clanlib-long-env-bo(7905)","refsource":"XF","url":"http://www.iss.net/security_center/static/7905.php"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0125","datePublished":"2002-03-15T05:00:00.000Z","dateReserved":"2002-03-15T00:00:00.000Z","dateUpdated":"2024-08-08T02:35:17.531Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-03-25 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:clanlib:clanlib:0.5:*:*:*:*:*:*:*","matchCriteriaId":"37EA0696-F688-473A-861A-29DDE234BC35"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"125","Ordinal":"1","Title":"CVE-2002-0125","CVE":"CVE-2002-0125","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"125","Ordinal":"1","NoteData":"Buffer overflow in ClanLib library 0.5 may allow local users to execute arbitrary code in games that use the library, such as (1) Super Methane Brothers, (2) Star War, (3) Kwirk, (4) Clankanoid, and others, via a long HOME environment variable.","Type":"Description","Title":"CVE-2002-0125"},{"CveYear":"2002","CveId":"125","Ordinal":"2","NoteData":"2002-03-15","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"125","Ordinal":"3","NoteData":"2002-03-22","Type":"Other","Title":"Modified"}]}}}