vendor:
Silly Poker
by:
demz
7.2
CVSS
HIGH
Buffer Overrun
120
CWE
Product Name: Silly Poker
Affected Version From: Silly Poker v0.25.5
Affected Version To: Silly Poker v0.25.5
Patch Exists: YES
Related CWE: N/A
CPE: //a:sillypoker:sillypoker:0.25.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Debian 3.1
2004
Local Buffer Overrun Vulnerability in Silly Poker
A local buffer overrun vulnerability has been reported for Silly Poker. The problem occurs due to insufficient bounds checking when handling user-supplied data. As a result, an attacker may be capable of controlling the execution flow of the sillypoker program and effectivley executing arbitrary code with elevated privileges.
Mitigation:
Perform proper bounds checking when handling user-supplied data.