GTetrinet: Remote code execution GTetrinet is vulnerable to a remote buffer overflow, potentially leading to arbitrary code execution. GTetrinet 2006-09-06 2006-09-07 144867 remote 0.7.10 0.7.10

GTetrinet is a networked Tetris clone for GNOME 2.

Michael Gehring has found that GTetrinet fails to properly handle array indexes.

An attacker can potentially execute arbitrary code by sending a negative number of players to the server.

There is no known workaround at this time.

All GTetrinet users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=games-puzzle/gtetrinet-0.7.10"
CVE-2006-3125 jaervosz daxomatic jaervosz