Bug#792420: zsnes: emulator escape vulnerability

2015-07-14 Thread Paul Wise
Package: zsnes Severity: important Tags: security X-Debbugs-CC: secur...@debian.org, sergio_...@yahoo.com.br According to this Youtube video and forum post, there are at least 3 vulnerabilities in zsnes that allow ROMs to escape the zsnes emulator and execute arbitrary code on the host running

Bug#792420: zsnes: emulator escape vulnerability

2015-07-14 Thread Etienne Millon
* Paul Wise p...@debian.org [150714 18:20]: According to this Youtube video and forum post, there are at least 3 vulnerabilities in zsnes that allow ROMs to escape the zsnes emulator and execute arbitrary code on the host running zsnes. The known issues will be fixed in 1.52 but there may be

Bug#792420: zsnes: emulator escape vulnerability

2015-07-14 Thread Paul Wise
On Tue, 2015-07-14 at 18:57 +0200, Etienne Millon wrote: While neither the exploit code nor a fix is out, I believe that the best course of action is indeed to write a patch for #610313. Sergio confirmed with the author that the issues are not in the C code but in the assembly, from the

Bug#792420: zsnes: emulator escape vulnerability

2015-07-14 Thread Alfred Agrell
On Tue, 14 Jul 2015 18:57:02 +0200 Etienne Millon m...@emillon.org wrote: * Paul Wise p...@debian.org [150714 18:20]: According to this Youtube video and forum post, there are at least 3 vulnerabilities in zsnes that allow ROMs to escape the zsnes emulator and execute arbitrary code on the