LTris is vulnerable to a buffer overflow which could lead to the execution of arbitrary code.
Package | games-puzzle/ltris on all architectures |
---|---|
Affected versions | < 1.0.10 |
Unaffected versions | >= 1.0.10 |
LTris is a Tetris clone.
LTris is vulnerable to a buffer overflow when reading the global highscores file.
By modifying the global highscores file a malicious user could trick another user to execute arbitrary code.
There is no known workaround at this time.
All LTris users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=games-puzzle/ltris-1.0.10"
Release date
March 20, 2005
Latest revision
March 20, 2005: 01
Severity
normal
Exploitable
local
Bugzilla entries