Xtokkaetama Nickname Local Buffer Overflow Vulnerability
BID:8337
Info
Xtokkaetama Nickname Local Buffer Overflow Vulnerability
| Bugtraq ID: | 8337 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 04 2003 12:00AM |
| Updated: | Aug 04 2003 12:00AM |
| Credit: | Discovery is credited to Vade 79 <[email protected]>. |
| Vulnerable: |
xtokkaetama xtokkaetama 1.0 b-6 |
| Not Vulnerable: | |
Discussion
Xtokkaetama Nickname Local Buffer Overflow Vulnerability
xtokkaetama is prone to a locally exploitable buffer overflow vulnerability. This is due to insufficient bounds checking of the '-nickname' command line option, which could result in execution of arbitrary code in the context of the software.
The software is typically installed setgid 'games'.
It should be noted that this issue was not patched in the updates provided in BID 8312.
xtokkaetama is prone to a locally exploitable buffer overflow vulnerability. This is due to insufficient bounds checking of the '-nickname' command line option, which could result in execution of arbitrary code in the context of the software.
The software is typically installed setgid 'games'.
It should be noted that this issue was not patched in the updates provided in BID 8312.
Exploit / POC
Xtokkaetama Nickname Local Buffer Overflow Vulnerability
The following exploits are available:
The following exploits are available:
Solution / Fix
Xtokkaetama Nickname Local Buffer Overflow Vulnerability
Solution:
Debian has released an advisory (DSA 367-1) that addresses this issue. Please see the attached advisory for details on obtaining and applying fixes.
xtokkaetama xtokkaetama 1.0 b-6
Solution:
Debian has released an advisory (DSA 367-1) that addresses this issue. Please see the attached advisory for details on obtaining and applying fixes.
xtokkaetama xtokkaetama 1.0 b-6
-
Debian xtokkaetama_1.0b-6woody2_alpha.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/x/xtokkaetama/xtokkaetama _1.0b-6woody2_alpha.deb -
Debian xtokkaetama_1.0b-6woody2_arm.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/x/xtokkaetama/xtokkaetama _1.0b-6woody2_arm.deb -
Debian xtokkaetama_1.0b-6woody2_hppa.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/x/xtokkaetama/xtokkaetama _1.0b-6woody2_hppa.deb -
Debian xtokkaetama_1.0b-6woody2_i386.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/x/xtokkaetama/xtokkaetama _1.0b-6woody2_i386.deb -
Debian xtokkaetama_1.0b-6woody2_ia64.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/x/xtokkaetama/xtokkaetama _1.0b-6woody2_ia64.deb -
Debian xtokkaetama_1.0b-6woody2_m68k.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/x/xtokkaetama/xtokkaetama _1.0b-6woody2_m68k.deb -
Debian xtokkaetama_1.0b-6woody2_mips.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/x/xtokkaetama/xtokkaetama _1.0b-6woody2_mips.deb -
Debian xtokkaetama_1.0b-6woody2_mipsel.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/x/xtokkaetama/xtokkaetama _1.0b-6woody2_mipsel.deb -
Debian xtokkaetama_1.0b-6woody2_powerpc.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/x/xtokkaetama/xtokkaetama _1.0b-6woody2_powerpc.deb -
Debian xtokkaetama_1.0b-6woody2_s390.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/x/xtokkaetama/xtokkaetama _1.0b-6woody2_s390.deb -
Debian xtokkaetama_1.0b-6woody2_sparc.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/x/xtokkaetama/xtokkaetama _1.0b-6woody2_sparc.deb
References
Xtokkaetama Nickname Local Buffer Overflow Vulnerability
References:
References: