On Sun, Jan 02, 2011 at 08:14:17PM +0200, Stefano Rivera wrote:
Package: pytris
Version: 0.98+nmu1
Severity: grave
Tags: security
Justification: user security hole
The setgid wrapper for this game makes no attempt at security.
...
I believe the best solution is removal, from
Package: pytris
Version: 0.98+nmu1
Severity: grave
Tags: security
Justification: user security hole
The setgid wrapper for this game makes no attempt at security.
It can trivially be used to execute code as group games, which can be
used to exploit other players of the game via the score file.
2 matches
Mail list logo