LWN.net Logo

irrlicht: arbitrary code execution

Package(s):irrlicht CVE #(s):CVE-2008-5876
Created:March 9, 2009 Updated:March 11, 2009
Description:

From the Gentoo advisory:

An unspecified component of the B3D loader is vulnerable to a buffer overflow due to missing boundary checks.

A remote attacker could entice a user to open a specially crafted .irr file, possibly resulting in the execution of arbitrary code with the privileges of the user running the application, or a Denial of Service (crash).

Alerts:
Gentoo 200903-10 2009-03-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds