VDB
CVE-2006-1390
CVE-2006-1390
PUBLISHED
CVSS 4.599999904632568 MEDIUM
The configuration of NetHack 3.4.3-r1 and earlier, Falcon's Eye 1.9.4a and earlier, and Slash'EM 0.0.760 and earlier on Gentoo Linux allows local users in the games group to modify saved games files to execute arbitrary code via buffer overflows and overwrite arbitrary files via symlink attacks.
EPSS 0.22% · 44.6th percentile
Risk Scores
CVSS 2.0
4.599999904632568
EPSS Score
0.22%
44.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| gentoo | linux | 0.7, 0.5, 1.4 |
| n/a | n/a | * |
Timeline
- Mar 25, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- 19376 third-party-advisory
- GLSA-200603-23 vendor-advisory
- http://bugs.gentoo.org/show_bug.cgi?id=125902 url
- http://bugs.gentoo.org/show_bug.cgi?id=127167 url
- http://bugs.gentoo.org/show_bug.cgi?id=127319 url
- 20060324 Re: [ GLSA 200603-23 ] NetHack, Slash'EM, Falcon's Eye: Localprivilege escalation mailing-list
- gentoo-multiple-games-privilege-escalation(25528) vdb
- 20060324 Re: [ GLSA 200603-23 ] NetHack, Slash'EM, Falcon's Eye: Local privilege escalation mailing-list
- http://bugs.gentoo.org/show_bug.cgi?id=122376 url
- 24104 vdb
- 17217 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2006-1390 advisory