vendor:
GNU Chess
by:
ace and t0asty
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: GNU Chess
Affected Version From: All versions
Affected Version To: All versions
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Red Hat 7.3
2002
Local Buffer Overflow in GNU Chess
A local buffer overflow has been reported for GNU Chess that may result in an attacker obtaining elevated privileges. The vulnerability exists due to insufficient boundary checks performed on some commandline options. Successful exploitation may result in the execution of attacker-supplied code. To be exploited for elevated privileges, the software must be setuid or setgid.
Mitigation:
Ensure that the software is not setuid or setgid and perform boundary checks on commandline options.