CVE-2003-1446: Buffer Overflow
Published Dec 31, 2003
·Updated
Buffer overflow in the saveintofile function in save.c for Rogue 5.2-2 allows local users to execute arbitrary code with games group privileges by setting a long HOME environment variable and invoking the save game function with a ~ (tilde).
Affected Software
2 affected components
Rogue Rogue=985.0
Rogue Rogue=5.2-2
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Oct 23, 2007
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1446?
CVE-2003-1446 is considered a high severity vulnerability due to the potential for local users to execute arbitrary code.
2
How do I fix CVE-2003-1446?
To fix CVE-2003-1446, update to the latest version of Rogue that addresses this buffer overflow vulnerability.
3
Who is affected by CVE-2003-1446?
Local users running Rogue versions 5.2-2 and 985.0 are affected by CVE-2003-1446.
4
What type of vulnerability is CVE-2003-1446?
CVE-2003-1446 is a buffer overflow vulnerability.
5
Can CVE-2003-1446 be exploited remotely?
No, CVE-2003-1446 can only be exploited locally by authenticated users.