vendor:
hack rougelike game GENOCIDE
by:
JMIT
8,8
CVSS
HIGH
Stack Overflow
121
CWE
Product Name: hack rougelike game GENOCIDE
Affected Version From: NetBSD 5.0 and below
Affected Version To: NetBSD 5.0 and below
Patch Exists: YES
Related CWE: Not available. See NetBSD-SA2009-007
CPE: NetBSD
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: NetBSD 5.0-RELEASE
2010
hack rougelike game GENOCIDE stack overflow
NetBSD 5.0 and below Hack GENOCIDE Environment overflow proof of concept. Successful exploitation gives guid 100 (games). Vulnerable Function is in hack.main.c. /usr/games/hack -D use the wizard mode. Only work in wizard mode. It is a basic strcpy stack overflow. Such overflows are hard to exploit in NetBSD.
Mitigation:
Apply the patch provided by the vendor or upgrade to the latest version of the software.