Package: xdigger
Version: 1.0.10-13
Severity: important
Tags: security

There is a buffer overflow in xdigger.

xdigger_1.0.10/xdigger.c
  strcpy(progname, argv[0]);

I confirmed execv* with a long argv[0] crashes xdigger.

Some other cases in the sound module with copying and strcating pargv/argv
might be worth looking at also. I have not investigated further. Nor have I
investigated exploitability.

xdigger is SGID games.

Reply via email to