Executive Summary
Summary | |
---|---|
Title | New crawl packages fix potential group games execution |
Informations | |||
---|---|---|---|
Name | DSA-949 | First vendor Publication | 2006-01-20 |
Vendor | Debian | Last vendor Modification | 2006-01-20 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 7.2 | Attack Range | Local |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Steve Kemp from the Debian Security Audit project discovered a security related problem in crawl, another console based dungeon exploration game in the vein of nethack and rogue. The program executes commands insecurely when saving or loading games which can allow local attackers to gain group games privileges. For the old stable distribution (woody) this problem has been fixed in version 4.0.0beta23-2woody2. For the stable distribution (sarge) this problem has been fixed in version 4.0.0beta26-4sarge0. For the unstable distribution (sid) this problem has been fixed in version 4.0.0beta26-7. We recommend that you upgrade your crawl package. |
Original Source
Url : http://www.debian.org/security/2006/dsa-949 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2008-01-17 | Name : Debian Security Advisory DSA 949-1 (crawl) File : nvt/deb_949_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
22690 | Linleys Dungeon Crawl Arbitrary Command Execution Dungeon Crawl contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered because the program executes programs in an insecure manner when saving or loading games, allowing a local user to gain 'games' group privileges. This flaw may lead to a loss of integrity. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2006-10-14 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-949.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2016-04-26 17:43:18 |
|
2014-02-17 11:34:50 |
|