Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 129954 - cheating allowed
Summary: cheating allowed
Status: RESOLVED DUPLICATE of bug 125902
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Games
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-04-14 08:35 UTC by Carsten Lohrke (RETIRED)
Modified: 2006-04-14 09:03 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carsten Lohrke (RETIRED) gentoo-dev 2006-04-14 08:35:15 UTC
Users playing games have to be in the games group. Games with systemwide highscores install into /var/games with 664, so every user allowed to play games can modify the scores. If he finds an application that doesn't expect arbitrary data as scores to load, he might be able to inject malicious code to be run, when another user loads the scores file next time.
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2006-04-14 09:03:17 UTC

*** This bug has been marked as a duplicate of 125902 ***