CVE-2019-15767
published 2019-08-29CVE-2019-15767: In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file.
PriorityP335high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.47%
70.9th percentile
In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnuchess | < gnuchess 6.2.7-1 (bookworm) | gnuchess 6.2.7-1 (bookworm) |
| gnu | chess | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7r53-xj4v-5fr4: In GNU Chess 6
ghsa_unreviewed·2022-05-24
CVE-2019-15767 [HIGH] GHSA-7r53-xj4v-5fr4: In GNU Chess 6
In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file.
OSV
CVE-2019-15767: In GNU Chess 6
osv·2019-08-29·CVSS 7.8
CVE-2019-15767 [HIGH] CVE-2019-15767: In GNU Chess 6
In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file.
Red Hat
gnuchess: stack-based overflow in cmd_load in frontend/cmd.cc via crafted EPD file
vendor_redhat·2019-08-28·CVSS 7.8
CVE-2019-15767 [HIGH] CWE-20 gnuchess: stack-based overflow in cmd_load in frontend/cmd.cc via crafted EPD file
gnuchess: stack-based overflow in cmd_load in frontend/cmd.cc via crafted EPD file
In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file.
Statement: This issue did not affect the versions of gnuchess as shipped with Red Hat Enterprise Linux 6 as the vulnerable code is not present in the older version shipped there.
Package: gnuchess (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2019-15767: gnuchess - In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load funct...
vendor_debian·2019·CVSS 7.8
CVE-2019-15767 [HIGH] CVE-2019-15767: gnuchess - In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load funct...
In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file.
Scope: local
bookworm: resolved (fixed in 6.2.7-1)
bullseye: resolved (fixed in 6.2.7-1)
forky: resolved (fixed in 6.2.7-1)
sid: resolved (fixed in 6.2.7-1)
trixie: resolved (fixed in 6.2.7-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-15767 gnuchess: stack-based overflow in cmd_load in frontend/cmd.cc via crafted EPD file [fedora-all]
bugzilla·2019-09-05·CVSS 7.8
CVE-2019-15767 [HIGH] CVE-2019-15767 gnuchess: stack-based overflow in cmd_load in frontend/cmd.cc via crafted EPD file [fedora-all]
CVE-2019-15767 gnuchess: stack-based overflow in cmd_load in frontend/cmd.cc via crafted EPD file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue af
Bugzilla
CVE-2019-15767 gnuchess: stack-based overflow in cmd_load in frontend/cmd.cc via crafted EPD file [epel-7]
bugzilla·2019-09-05·CVSS 7.8
CVE-2019-15767 [HIGH] CVE-2019-15767 gnuchess: stack-based overflow in cmd_load in frontend/cmd.cc via crafted EPD file [epel-7]
CVE-2019-15767 gnuchess: stack-based overflow in cmd_load in frontend/cmd.cc via crafted EPD file [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the follow
Bugzilla
CVE-2019-15767 gnuchess: stack-based overflow in cmd_load in frontend/cmd.cc via crafted EPD file
bugzilla·2019-09-05·CVSS 7.8
CVE-2019-15767 [HIGH] CVE-2019-15767 gnuchess: stack-based overflow in cmd_load in frontend/cmd.cc via crafted EPD file
CVE-2019-15767 gnuchess: stack-based overflow in cmd_load in frontend/cmd.cc via crafted EPD file
A vulnerability was found in GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load
function in frontend/cmd.cc via a crafted chess position in an EPD file.
Reference:
https://lists.gnu.org/archive/html/bug-gnu-chess/2019-08/msg00004.html
https://lists.gnu.org/archive/html/bug-gnu-chess/2019-08/msg00005.html
Discussion:
Created gnuchess tracking bugs for this issue:
Affects: epel-7 [bug 1749178]
Affects: fedora-all [bug 1749177]
---
gnuchess is only shipped in the optional repository.
---
Statement:
This issue did not affect the versions of gnuchess as shipped with Red Hat Enterprise Linux 6 as the vulnerable code is not present in the older version shipped there.
-
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZA4UCVURQXNLUNFAMRLZBAFRHSEVC6Q/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TB4FURVE4C35UDXGAAHJL5NIHJQ3WDZT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TGIICRUZRFAK5M7SNHZKR7SKE77SFKWE/https://lists.gnu.org/archive/html/bug-gnu-chess/2019-08/msg00004.htmlhttps://lists.gnu.org/archive/html/bug-gnu-chess/2019-08/msg00005.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZA4UCVURQXNLUNFAMRLZBAFRHSEVC6Q/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TB4FURVE4C35UDXGAAHJL5NIHJQ3WDZT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TGIICRUZRFAK5M7SNHZKR7SKE77SFKWE/https://lists.gnu.org/archive/html/bug-gnu-chess/2019-08/msg00004.htmlhttps://lists.gnu.org/archive/html/bug-gnu-chess/2019-08/msg00005.html
2019-08-29
Published