Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 138117 - games-arcade/emilia-pinball: 0.3.1 privilege escalation vuln (CVE-2006-2196)
Summary: games-arcade/emilia-pinball: 0.3.1 privilege escalation vuln (CVE-2006-2196)
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://cve.mitre.org/cgi-bin/cvename....
Whiteboard: B3? [ebuild] Falco
Keywords:
Depends on:
Blocks:
 
Reported: 2006-06-26 15:26 UTC by Raphael Marichez (Falco) (RETIRED)
Modified: 2006-06-26 15:55 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-26 15:26:21 UTC
SA 20778 :


Software:	Emilia Pinball 0.x

Description:
A vulnerability has been reported in Pinball, which can be exploited by malicious, local users to gain escalated privileges.

The vulnerability is caused due to an input validation error when loading compiled plugins. This can be exploited to cause the application to load plugins from user-controlled directories without dropping privileges.

Successful exploitation may allow the user to perform certain actions with privileges of the "games" user.

The vulnerability has been reported in version 0.3.1. Other versions may also be affected.

Solution:
Restrict access to trusted users only.

Some Linux vendors have released fixed packages.

Provided and/or discovered by:
Steve Kemp

Original Advisory:
Debian:
http://www.us.debian.org/security/2006/dsa-1102
Comment 1 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-26 15:40:49 UTC
Hi games team, a patch is available on debian. Unfortunately, as usual, their patch concerns many other issues.
Comment 2 SpanKY gentoo-dev 2006-06-26 15:45:38 UTC
not like we're vuln anyways ;)
Comment 3 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-26 15:55:20 UTC
(In reply to comment #2)
> not like we're vuln anyways ;)
> 

mmm.... yes, that's a silly thing. Forget that.
Gentoo rulez :)

mv bug138117 /dev/trash (feel free to reopen if i'm wrong)