CVE-2006-1390: Buffer Overflow
The configuration of NetHack 3.4.3-r1 and earlier, Falcon's Eye 1.9.4a and earlier, and Slash'EM 0.0.760 and earlier on Gentoo Linux allows local users in the games group to modify saved games files to execute arbitrary code via buffer overflows and overwrite arbitrary files via symlink attacks.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1390?
CVE-2006-1390 is considered a high-severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2006-1390?
To fix CVE-2006-1390, update to a version of NetHack, Falcon's Eye, or Slash'EM that is not affected by the vulnerability.
Who is affected by CVE-2006-1390?
CVE-2006-1390 affects local users in the games group on Gentoo Linux who have access to the vulnerable game files.
What types of attacks can be executed through CVE-2006-1390?
CVE-2006-1390 can be exploited via buffer overflows and symlink attacks leading to arbitrary file modification and code execution.
Which versions of Gentoo Linux are affected by CVE-2006-1390?
Gentoo Linux versions 1.1a, 1.2, 1.4 (including release candidates), and 0.5-0.7 are affected by CVE-2006-1390.