Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 138117

Summary: games-arcade/emilia-pinball: 0.3.1 privilege escalation vuln (CVE-2006-2196)
Product: Gentoo Security Reporter: Raphael Marichez (Falco) (RETIRED) <falco>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED INVALID    
Severity: minor CC: games
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2196
Whiteboard: B3? [ebuild] Falco
Package list:
Runtime testing required: ---

Description Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-26 15:26:21 UTC
SA 20778 :


Software:	Emilia Pinball 0.x

Description:
A vulnerability has been reported in Pinball, which can be exploited by malicious, local users to gain escalated privileges.

The vulnerability is caused due to an input validation error when loading compiled plugins. This can be exploited to cause the application to load plugins from user-controlled directories without dropping privileges.

Successful exploitation may allow the user to perform certain actions with privileges of the "games" user.

The vulnerability has been reported in version 0.3.1. Other versions may also be affected.

Solution:
Restrict access to trusted users only.

Some Linux vendors have released fixed packages.

Provided and/or discovered by:
Steve Kemp

Original Advisory:
Debian:
http://www.us.debian.org/security/2006/dsa-1102
Comment 1 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-26 15:40:49 UTC
Hi games team, a patch is available on debian. Unfortunately, as usual, their patch concerns many other issues.
Comment 2 SpanKY gentoo-dev 2006-06-26 15:45:38 UTC
not like we're vuln anyways ;)
Comment 3 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-26 15:55:20 UTC
(In reply to comment #2)
> not like we're vuln anyways ;)
> 

mmm.... yes, that's a silly thing. Forget that.
Gentoo rulez :)

mv bug138117 /dev/trash (feel free to reopen if i'm wrong)