Name | CVE-2006-0176 |
Description | Buffer overflow in certain functions in src/fileio.c and src/unix/fileio.c in xmame before 11 January 2006 may allow local users to gain privileges via a long (1) -lang, (2) -ctrlr, (3) -pb, or (4) -rec argument on many operating systems, and via a long (5) -jdev argument on Ubuntu Linux. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 349653 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
xmame | source | (unstable) | 0.104-1 | medium | 349653 |
Only xmame-svgalib is vulnerable, the xmame-x package has a debconf
question, that makes it very clear that setuid root is only for single-user
systems and xmame-sdl and xmess aren't setuid at all
[sarge] - xmame <no-dsa> (XMame is non-free software)