Secunia Logo
 
XGalaga HOME Environment Variable Buffer Overflow Vulnerability
Secunia Advisory: SA9138
Release Date: 2003-06-30
Popularity: 7,526 views

Critical:
Not critical
Impact: Privilege escalation
Where: Local system
Solution Status: Vendor Patch

OS:Debian GNU/Linux 3.0
Debian GNU/Linux unstable alias sid

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2003-0454


Description:
Debian has reported a vulnerability in XGalaga, which can be exploited by malicious, local users to escalate their privileges.

The vulnerability is caused due to a boundary error in the handling of the HOME environment variable. This can be exploited to cause a buffer overflow making it possible to execute arbitrary code with the privileges of the "games" group.

Solution:
Updated packages:

-- Debian GNU/Linux 3.0 alias woody --

Source archives:

http://security.debian.org/pool/updat...x/xgalaga/xgalaga_2.0.34-19woody1.dsc
Size/MD5 checksum: 576 746a62bbc0e1fe3e402ebf0baf7d409f
http://security.debian.org/pool/updat...alaga/xgalaga_2.0.34-19woody1.diff.gz
Size/MD5 checksum: 33875 cca65c5c025fe964e574ed286bf1a48e
http://security.debian.org/pool/updat.../x/xgalaga/xgalaga_2.0.34.orig.tar.gz
Size/MD5 checksum: 314189 9f7ee685e9c4741b5f0edc3f91df9510

Alpha architecture:

http://security.debian.org/pool/updat...aga/xgalaga_2.0.34-19woody1_alpha.deb
Size/MD5 checksum: 208352 2ee48a6c41ed2912f9c04b7e5bab0b2f

ARM architecture:

http://security.debian.org/pool/updat...alaga/xgalaga_2.0.34-19woody1_arm.deb
Size/MD5 checksum: 198666 3bba4b2486e3c48f6d116f55b521180d

Intel IA-32 architecture:

http://security.debian.org/pool/updat...laga/xgalaga_2.0.34-19woody1_i386.deb
Size/MD5 checksum: 191654 4fd57335930cb976e93b48993fc159e0

Intel IA-64 architecture:

http://security.debian.org/pool/updat...laga/xgalaga_2.0.34-19woody1_ia64.deb
Size/MD5 checksum: 225428 0030ed8957fda5d7787415deceb05b41

HP Precision architecture:

http://security.debian.org/pool/updat...laga/xgalaga_2.0.34-19woody1_hppa.deb
Size/MD5 checksum: 211990 8877bd894336e2b4eeae5e90bb76bae9

Motorola 680x0 architecture:

http://security.debian.org/pool/updat...laga/xgalaga_2.0.34-19woody1_m68k.deb
Size/MD5 checksum: 192832 5edfdbf20d05364609abd78121e86839

Big endian MIPS architecture:

http://security.debian.org/pool/updat...laga/xgalaga_2.0.34-19woody1_mips.deb
Size/MD5 checksum: 205460 928639b6561e32e4e8f7820dbae789ed

Little endian MIPS architecture:

http://security.debian.org/pool/updat...ga/xgalaga_2.0.34-19woody1_mipsel.deb
Size/MD5 checksum: 202588 27e65f0489cee88c3b2af603764ae66f

PowerPC architecture:

http://security.debian.org/pool/updat...a/xgalaga_2.0.34-19woody1_powerpc.deb
Size/MD5 checksum: 199984 f0baf858ea5f44368fe14fceb581862f

IBM S/390 architecture:

http://security.debian.org/pool/updat...laga/xgalaga_2.0.34-19woody1_s390.deb
Size/MD5 checksum: 200876 a816f3a90931f141ed0d0450d77feb44

Sun Sparc architecture:

http://security.debian.org/pool/updat...aga/xgalaga_2.0.34-19woody1_sparc.deb
Size/MD5 checksum: 205648 ce754d6e1665737c7160a14ca47d21f8


-- Debian GNU/Linux unstable alias sid --

Fixed in version 2.0.34-22.

Provided and/or discovered by:
Steve Kemp

Original Advisory:
http://www.debian.org/security/2003/dsa-334


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 57 views
2. Adobe Acrobat/Reader Multiple Vulnerabilities // 32 views
3. ClamAV "cli_check_jpeg_exploit()" Denial of Service Vulnerability // 30 views
4. Linksys WRT160N Cross-Site Scripting Vulnerability // 29 views
5. IBM Rational ClearQuest Multiple Vulnerabilities // 26 views
6. IBM Rational ClearCase Cross-Site Scripting Vulnerability // 24 views
7. Rumpus Multiple Vulnerabilities // 24 views
8. Debian update for flamethrower // 23 views
9. bcoos "cid" SQL Injection Vulnerability // 22 views
10. ASP Portal "ASPPortal.mdb" Database Disclosure Security Issue // 20 views