GLSA-200603-23 : NetHack, Slash'EM, Falcon's Eye: Local privilege escalation

medium Nessus Plugin ID 21147

Synopsis

The remote Gentoo host is missing one or more security-related patches.

Description

The remote host is affected by the vulnerability described in GLSA-200603-23 (NetHack, Slash'EM, Falcon's Eye: Local privilege escalation)

NetHack, Slash'EM and Falcon's Eye have been found to be incompatible with the system used for managing games on Gentoo Linux. As a result, they cannot be played securely on systems with multiple users.
Impact :

A local user who is a member of group 'games' may be able to modify the state data used by NetHack, Slash'EM or Falcon's Eye to trigger the execution of arbitrary code with the privileges of other players.
Additionally, the games may create save game files in a manner not suitable for use on Gentoo Linux, potentially allowing a local user to create or overwrite files with the permissions of other players.
Workaround :

Do not add untrusted users to the 'games' group.

Solution

NetHack has been masked in Portage pending the resolution of these issues. Vulnerable NetHack users are advised to uninstall the package until further notice.
# emerge --ask --verbose --unmerge 'games-roguelike/nethack' Slash'EM has been masked in Portage pending the resolution of these issues. Vulnerable Slash'EM users are advised to uninstall the package until further notice.
# emerge --ask --verbose --unmerge 'games-roguelike/slashem' Falcon's Eye has been masked in Portage pending the resolution of these issues. Vulnerable Falcon's Eye users are advised to uninstall the package until further notice.
# emerge --ask --verbose --unmerge 'games-roguelike/falconseye'

See Also

https://security.gentoo.org/glsa/200603-23

Plugin Details

Severity: Medium

ID: 21147

File Name: gentoo_GLSA-200603-23.nasl

Version: 1.15

Type: local

Published: 3/27/2006

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.3

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:gentoo:linux:falconseye, p-cpe:/a:gentoo:linux:nethack, p-cpe:/a:gentoo:linux:slashem, cpe:/o:gentoo:linux

Required KB Items: Host/local_checks_enabled, Host/Gentoo/release, Host/Gentoo/qpkg-list

Patch Publication Date: 3/23/2006

Vulnerability Publication Date: 2/10/2006

Reference Information

CVE: CVE-2006-1390

GLSA: 200603-23