CVE-2006-0176

NameCVE-2006-0176
DescriptionBuffer overflow in certain functions in src/fileio.c and src/unix/fileio.c in xmame before 11 January 2006 may allow local users to gain privileges via a long (1) -lang, (2) -ctrlr, (3) -pb, or (4) -rec argument on many operating systems, and via a long (5) -jdev argument on Ubuntu Linux.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs349653

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xmamesource(unstable)0.104-1medium349653

Notes

Only xmame-svgalib is vulnerable, the xmame-x package has a debconf
question, that makes it very clear that setuid root is only for single-user
systems and xmame-sdl and xmess aren't setuid at all
[sarge] - xmame <no-dsa> (XMame is non-free software)

Search for package or bug name: Reporting problems