Vulnerability Description
Buffer overflow in lbreakout2 allows local users to gain 'games' group privileges via a large HOME environment variable to (1) editor.c, (2) theme.c, (3) manager.c, (4) config.c, (5) game.c, (6) levels.c, or (7) main.c.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lgames | Lbreakout2 | 2.0 |
References
- http://marc.info/?l=bugtraq&m=107755821705356&w=2
- http://security.debian.org/pool/updates/main/l/lbreakout2/lbreakout2_2.2.2-1wood
- http://www.debian.org/security/2004/dsa-445PatchVendor Advisory
- http://www.securityfocus.com/bid/9712ExploitPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15229
- http://marc.info/?l=bugtraq&m=107755821705356&w=2
- http://security.debian.org/pool/updates/main/l/lbreakout2/lbreakout2_2.2.2-1wood
- http://www.debian.org/security/2004/dsa-445PatchVendor Advisory
- http://www.securityfocus.com/bid/9712ExploitPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15229
FAQ
What is CVE-2004-0158?
CVE-2004-0158 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Buffer overflow in lbreakout2 allows local users to gain 'games' group privileges via a large HOME environment variable to (1) editor.c, (2) theme.c, (3) manager.c, (4) config.c, (5) game.c, (6) level...
How severe is CVE-2004-0158?
CVE-2004-0158 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-0158?
Check the references section above for vendor advisories and patch information. Affected products include: Lgames Lbreakout2.