From 9bfaf9c524d4a278d024ff8dd9f432304aa047d3 Mon Sep 17 00:00:00 2001 From: Jacques Vidrine Date: Mon, 16 Aug 2004 22:38:28 +0000 Subject: Document a setgid "games" security issue in xonix. Based on a VuXML entry that was Submitted by: robert@OpenBSD.org --- security/vuxml/vuln.xml | 30 ++++++++++++++++++++++++++++++ 1 file changed, 30 insertions(+) (limited to 'security') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 2c35e28c306a..7f0b9abc092d 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -32,6 +32,36 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. --> + + xonix -- failure to drop privileges + + + xonix + 1.4_1 + + + + +

A Debian security advisory reports:

+
+

Steve Kemp discovered a vulnerability in xonix, a game, + where an external program was invoked while retaining setgid + privileges. A local attacker could exploit this vulnerability + to gain gid "games".

+
+ +
+ + CAN-2004-0157 + http://www.debian.org/security/2004/dsa-484 + 10149 + + + 2004-04-14 + 2004-08-16 + +
+ Arbitrary code execution via a format string vulnerability -- cgit v1.2.3