All errata/sisyphus_riscv64/ALT-PU-2021-4738-1
ALT-PU-2021-4738-1

Package update chess in branch sisyphus_riscv64

Version6.2.9-alt1
Task#0
Published2021-12-25
Max severityHIGH
Severity:

Closed issues (2)

CVE-2021-30184
HIGH7.8

GNU Chess 6.2.7 allows attackers to execute arbitrary code via crafted PGN (Portable Game Notation) data. This is related to a buffer overflow in the use of a .tmp.epd temporary file in the cmd_pgnload and cmd_pgnreplay functions in frontend/cmd.cc.

Published: 2021-04-07Modified: 2025-01-12
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P
CVSS 3.xHIGH 7.8
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H