First published: Wed Dec 31 2003(Updated: )
Buffer overflow in the save_into_file function in save.c for Rogue 5.2-2 allows local users to execute arbitrary code with games group privileges by setting a long HOME environment variable and invoking the save game function with a ~ (tilde).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rogue Rogue | =985.0 | |
Rogue Rogue | =5.2-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1446 is considered a high severity vulnerability due to the potential for local users to execute arbitrary code.
To fix CVE-2003-1446, update to the latest version of Rogue that addresses this buffer overflow vulnerability.
Local users running Rogue versions 5.2-2 and 985.0 are affected by CVE-2003-1446.
CVE-2003-1446 is a buffer overflow vulnerability.
No, CVE-2003-1446 can only be exploited locally by authenticated users.