Linley Henzell Dungeon Crawl Unspecified Command Execution Vulnerability
BID:16337
Info
Linley Henzell Dungeon Crawl Unspecified Command Execution Vulnerability
| Bugtraq ID: | 16337 |
| Class: | Design Error |
| CVE: |
CVE-2006-0045 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 20 2006 12:00AM |
| Updated: | Feb 20 2007 08:56PM |
| Credit: | Steve Kemp discovered this issue. |
| Vulnerable: |
Linley Henzell Crawl 4.0 BETA 26 Linley Henzell Crawl 4.0 BETA 23 Linley Henzell Crawl 4.0 |
| Not Vulnerable: | |
Discussion
Linley Henzell Dungeon Crawl Unspecified Command Execution Vulnerability
Dungeon Crawl has been reported to be prone to an unspecified command-execution vulnerability.
Local attackers can trigger this vulnerability to execute arbitrary commands to gain group games privileges.
Dungeon Crawl has been reported to be prone to an unspecified command-execution vulnerability.
Local attackers can trigger this vulnerability to execute arbitrary commands to gain group games privileges.
Exploit / POC
Linley Henzell Dungeon Crawl Unspecified Command Execution Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Linley Henzell Dungeon Crawl Unspecified Command Execution Vulnerability
Solution:
Debian has released advisory DSA 949-1 to address this issue. Please see the referenced advisory for more information.
Solution:
Debian has released advisory DSA 949-1 to address this issue. Please see the referenced advisory for more information.
References
Linley Henzell Dungeon Crawl Unspecified Command Execution Vulnerability
References:
References:
- DSA-949-1 crawl (Debian)