Maelstrom Player Argument Buffer Overflow Vulnerability
BID:7632
Info
Maelstrom Player Argument Buffer Overflow Vulnerability
| Bugtraq ID: | 7632 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 20 2003 12:00AM |
| Updated: | May 20 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to [email protected]. |
| Vulnerable: |
Sam Lantinga Maelstrom 3.0.6 Sam Lantinga Maelstrom 3.0.5 Sam Lantinga Maelstrom 3.0.3 |
| Not Vulnerable: | |
Discussion
Maelstrom Player Argument Buffer Overflow Vulnerability
Maelstrom for Linux has been reported prone to a buffer overflow vulnerability.
The issue is reportedly due to a lack of sufficient bounds checking performed on user-supplied data before it is copied into an internal memory space. It may be possible for a local attacker to exploit this condition and have malicious arbitrary code executed in the context of the Maelstrom application. Typically setGID games.
It should be noted that although this vulnerability has been reported to affect Maelstrom version 3.0.6 and 3.0.5 previous versions might also be affected.
Maelstrom for Linux has been reported prone to a buffer overflow vulnerability.
The issue is reportedly due to a lack of sufficient bounds checking performed on user-supplied data before it is copied into an internal memory space. It may be possible for a local attacker to exploit this condition and have malicious arbitrary code executed in the context of the Maelstrom application. Typically setGID games.
It should be noted that although this vulnerability has been reported to affect Maelstrom version 3.0.6 and 3.0.5 previous versions might also be affected.
Exploit / POC
Maelstrom Player Argument Buffer Overflow Vulnerability
The following proof of concept exploit has been supplied by [email protected] and Knight420 respecitvely:
The following proof of concept exploit has been supplied by [email protected] and Knight420 respecitvely:
Solution / Fix
Maelstrom Player Argument Buffer Overflow Vulnerability
Solution:
Andrew Church has supplied an unsupported unofficial patch to address this issue for maelstrom version 3.0.6.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Sam Lantinga Maelstrom 3.0.6
Solution:
Andrew Church has supplied an unsupported unofficial patch to address this issue for maelstrom version 3.0.6.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Sam Lantinga Maelstrom 3.0.6
-
Andrew Church maelstrom-3.06.patch
http://downloads.securityfocus.com/vulnerabilities/patches/maelstrom-3 .06.patch
References
Maelstrom Player Argument Buffer Overflow Vulnerability
References:
References:
- Maelstrom Homepage (Sam Lantinga)
- Maelstrom bugfix (was Maelstrom Local Buffer Overflow Exploit, ([email protected] (Andrew Church))
- Maelstrom Local Buffer Overflow Exploit ("akcess ."
)