Debian Gnuchess vulnerabilities
3 known vulnerabilities affecting debian/gnuchess.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1LOW2
Vulnerabilities
Page 1 of 1
CVE-2015-8972P3LOWCVSS 9.8fixed in gnuchess 6.2.4-1 (bookworm)2015
CVE-2015-8972 [CRITICAL] CVE-2015-8972: gnuchess - Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in ...
Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 might allow context-dependent attackers to execute arbitrary code via a large input, as demonstrated when in UCI mode.
Scope: local
bookworm: resolved (fixed in 6.2.4-1)
bullseye: resolved (fixed in 6.2.4-1)
forky: resolved (fixed in 6.2.4-1)
sid:
debian
CVE-2021-30184P3HIGHCVSS 7.8fixed in gnuchess 6.2.7-1+deb12u1 (bookworm)2021
CVE-2021-30184 [HIGH] CVE-2021-30184: gnuchess - GNU Chess 6.2.7 allows attackers to execute arbitrary code via crafted PGN (Port...
GNU Chess 6.2.7 allows attackers to execute arbitrary code via crafted PGN (Portable Game Notation) data. This is related to a buffer overflow in the use of a .tmp.epd temporary file in the cmd_pgnload and cmd_pgnreplay functions in frontend/cmd.cc.
Scope: local
bookworm: resolved (fixed in 6.2.7-1+deb12u1)
bullseye: resolved (fixed in 6.2.7-1+deb11u1)
forky: resol
debian
CVE-2019-15767P3LOWCVSS 7.8fixed in gnuchess 6.2.7-1 (bookworm)2019
CVE-2019-15767 [HIGH] CVE-2019-15767: gnuchess - In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load funct...
In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file.
Scope: local
bookworm: resolved (fixed in 6.2.7-1)
bullseye: resolved (fixed in 6.2.7-1)
forky: resolved (fixed in 6.2.7-1)
sid: resolved (fixed in 6.2.7-1)
trixie: resolved (fixed in 6.2.7-1)
debian