Dopewars User-Supplied High Score File Disclosure/Overwrite Vulnerability
BID:5106
Info
Dopewars User-Supplied High Score File Disclosure/Overwrite Vulnerability
| Bugtraq ID: | 5106 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 26 2002 12:00AM |
| Updated: | Jun 26 2002 12:00AM |
| Credit: | This issue was publicized in the changelog for the product. |
| Vulnerable: |
Dopewars Dopewars 1.5.6 Dopewars Dopewars 1.5.5 Dopewars Dopewars 1.5.4 Dopewars Dopewars 1.5.3 Dopewars Dopewars 1.5.2 Dopewars Dopewars 1.5.1 Dopewars Dopewars 1.5 beta2 Dopewars Dopewars 1.5 beta1 Dopewars Dopewars 1.5 |
| Not Vulnerable: |
Dopewars Dopewars 1.5.7 |
Discussion
Dopewars User-Supplied High Score File Disclosure/Overwrite Vulnerability
Affected versions of Dopewars allow users to specify high score files. In the case that Dopewars is installed setuid/setgid, this may allow a local attacker to disclose the contents of files which are readable by the owner/group of the Dopewars binary. Additionally, an attacker may exploit this to overwrite files which are writeable by the owner/group of the Dopewars binary.
Affected versions of Dopewars allow users to specify high score files. In the case that Dopewars is installed setuid/setgid, this may allow a local attacker to disclose the contents of files which are readable by the owner/group of the Dopewars binary. Additionally, an attacker may exploit this to overwrite files which are writeable by the owner/group of the Dopewars binary.
Solution / Fix
Dopewars User-Supplied High Score File Disclosure/Overwrite Vulnerability
Solution:
The vendor has released an upgrade which addresses this issue.
Solution:
The vendor has released an upgrade which addresses this issue.
References
Dopewars User-Supplied High Score File Disclosure/Overwrite Vulnerability
References:
References:
- Dopewars Homepage (Dopewars)