CVE-2015-8972
published 2017-01-23CVE-2015-8972: Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 might allow context-dependent attackers…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.76%
88.7th percentile
Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 might allow context-dependent attackers to execute arbitrary code via a large input, as demonstrated when in UCI mode.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnuchess | < gnuchess 6.2.4-1 (bookworm) | gnuchess 6.2.4-1 (bookworm) |
| gnu | chess | < 6.2.4 | 6.2.4 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
gnuchess: Stack-based buffer overflow on user move input
vendor_redhat·2016-10-29·CVSS 9.8
CVE-2015-8972 [CRITICAL] CWE-121 gnuchess: Stack-based buffer overflow on user move input
gnuchess: Stack-based buffer overflow on user move input
Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 might allow context-dependent attackers to execute arbitrary code via a large input, as demonstrated when in UCI mode.
Package: gnuchess (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2015-8972: gnuchess - Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in ...
vendor_debian·2015·CVSS 9.8
CVE-2015-8972 [CRITICAL] CVE-2015-8972: gnuchess - Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in ...
Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 might allow context-dependent attackers to execute arbitrary code via a large input, as demonstrated when in UCI mode.
Scope: local
bookworm: resolved (fixed in 6.2.4-1)
bullseye: resolved (fixed in 6.2.4-1)
forky: resolved (fixed in 6.2.4-1)
sid: resolved (fixed in 6.2.4-1)
trixie: resolved (fixed in 6.2.4-1)
GHSA
GHSA-m3c3-j429-9q78: Stack-based buffer overflow in the ValidateMove function in frontend/move
ghsa_unreviewed·2022-05-13
CVE-2015-8972 [CRITICAL] CWE-119 GHSA-m3c3-j429-9q78: Stack-based buffer overflow in the ValidateMove function in frontend/move
Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 might allow context-dependent attackers to execute arbitrary code via a large input, as demonstrated when in UCI mode.
OSV
CVE-2015-8972: Stack-based buffer overflow in the ValidateMove function in frontend/move
osv·2017-01-23·CVSS 9.8
CVE-2015-8972 [CRITICAL] CVE-2015-8972: Stack-based buffer overflow in the ValidateMove function in frontend/move
Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 might allow context-dependent attackers to execute arbitrary code via a large input, as demonstrated when in UCI mode.
No detection rules found.
No public exploits indexed.
http://lists.gnu.org/archive/html/bug-gnu-chess/2015-10/msg00002.htmlhttp://svn.savannah.gnu.org/viewvc/chess?revision=134&view=revisionhttp://www.openwall.com/lists/oss-security/2016/11/13/2http://www.openwall.com/lists/oss-security/2016/11/14/11http://www.openwall.com/lists/oss-security/2016/11/14/12http://lists.gnu.org/archive/html/bug-gnu-chess/2015-10/msg00002.htmlhttp://svn.savannah.gnu.org/viewvc/chess?revision=134&view=revisionhttp://www.openwall.com/lists/oss-security/2016/11/13/2http://www.openwall.com/lists/oss-security/2016/11/14/11http://www.openwall.com/lists/oss-security/2016/11/14/12
2017-01-23
Published