vendor:
xsok
by:
n2n
7.2
CVSS
HIGH
Buffer Overrun
120
CWE
Product Name: xsok
Affected Version From: 01.02
Affected Version To: 01.02
Patch Exists: NO
Related CWE: N/A
CPE: a:xsok:xsok:1.02
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Redhat Linux 9.0
2004
xsok 1.02 local game exploit
xsok is prone to a locally exploitable buffer overrun vulnerability due to insufficient bounds check of data supplied through the LANG environment variable. This could be exploited to execute arbitrary code with elevated privileges. The program is typically installed setgid games.
Mitigation:
Ensure that the LANG environment variable is not set to a malicious value.