LWN.net Logo

crawl: buffer overflow

Package(s):crawl CVE #(s):CAN-2004-0103
Created:February 3, 2004 Updated:February 4, 2004
Description: Steve Kemp from the GNU/Linux audit project discovered a problem in crawl, another console based dungeon exploration game, in the vein of nethack and rogue. The program uses several environment variables as inputs but doesn't apply a size check before copying one of them into a fixed size buffer.
Alerts:
Debian DSA-432-1 2004-02-03

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds