vendor:
xtokkaetama
by:
gunzip
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: xtokkaetama
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, BSD
2002
xtokkaetama Buffer Overflow Vulnerability
xtokkaetama is prone to a locally exploitable buffer overflow vulnerability. This is due to insufficient bounds checking of the '-nickname' command line option, which could result in execution of arbitrary code in the context of the software. The software is typically installed setgid 'games'.
Mitigation:
Ensure that the software is not installed with setgid 'games' privileges.