Silly Poker Local HOME Environment Variable Buffer Overrun Vulnerability
BID:8736
Info
Silly Poker Local HOME Environment Variable Buffer Overrun Vulnerability
| Bugtraq ID: | 8736 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 30 2003 12:00AM |
| Updated: | Sep 30 2003 12:00AM |
| Credit: | This vulnerability was reported by "demz" <[email protected]>. |
| Vulnerable: |
Silly Poker Silly Poker 0.25.5 |
| Not Vulnerable: | |
Discussion
Silly Poker Local HOME Environment Variable Buffer Overrun Vulnerability
A local buffer overrun vulnerability has been reported for Silly Poker. The problem occurs due to insufficient bounds checking when handling user-supplied data. As a result, an attacker may be capable of controlling the execution flow of the sillypoker program and effectivley executing arbitrary code with elevated privileges.
A local buffer overrun vulnerability has been reported for Silly Poker. The problem occurs due to insufficient bounds checking when handling user-supplied data. As a result, an attacker may be capable of controlling the execution flow of the sillypoker program and effectivley executing arbitrary code with elevated privileges.
Exploit / POC
Silly Poker Local HOME Environment Variable Buffer Overrun Vulnerability
An exploit has been made available.
An exploit has been made available.
Solution / Fix
Silly Poker Local HOME Environment Variable Buffer Overrun Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Silly Poker Local HOME Environment Variable Buffer Overrun Vulnerability
References:
References: