vendor:
zblast
by:
v9
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: zblast
Affected Version From: v1.2
Affected Version To: v1.2
Patch Exists: YES
Related CWE: N/A
CPE: a:svgalib:zblast
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2002
zblast/xzb[v1.2] Local Buffer Overflow
A vulnerability has been reported for zblast, an svgalib-based game. The problem occurs when copying data from a user-supplied environment variable into a static memory buffer. By storing excessive data within the variable, it may be possible for an attacker to corrupt process memory, ultimately resulting in the execution of arbitrary code.
Mitigation:
Upgrade to the latest version of zblast/xzb