Mah-Jong MJ-Player Server Flag Local Buffer Overflow Vulnerability
BID:8729
Info
Mah-Jong MJ-Player Server Flag Local Buffer Overflow Vulnerability
| Bugtraq ID: | 8729 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 29 2003 12:00AM |
| Updated: | Sep 29 2003 12:00AM |
| Credit: | Discovery credited to jsk. |
| Vulnerable: |
Mah-Jong Mah-Jong 1.4 |
| Not Vulnerable: | |
Discussion
Mah-Jong MJ-Player Server Flag Local Buffer Overflow Vulnerability
A problem in the handling of large requests supplied with certain flags has been reported in Maj-Jong. Because of this, it may be possible for a local attacker to gain elevated privileges.
This vulnerability may be related to the issues described that were addressed in Debian Security Advisory DSA 378-1 and described in BID 8557.
A problem in the handling of large requests supplied with certain flags has been reported in Maj-Jong. Because of this, it may be possible for a local attacker to gain elevated privileges.
This vulnerability may be related to the issues described that were addressed in Debian Security Advisory DSA 378-1 and described in BID 8557.
Exploit / POC
Mah-Jong MJ-Player Server Flag Local Buffer Overflow Vulnerability
The following exploit has been made available by jsk.
The following exploit has been made available by jsk.
Solution / Fix
Mah-Jong MJ-Player Server Flag Local Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Mah-Jong MJ-Player Server Flag Local Buffer Overflow Vulnerability
References:
References:
- mah-jong Package Reference (Debian GNU/Linux)