Debian Security Advisory
DSA-856-1 py2play -- design error
- Date Reported:
- 10 Oct 2005
- Affected Packages:
- py2play
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 326976.
In Mitre's CVE dictionary: CVE-2005-2875. - More information:
-
Arc Riley discovered that py2play, a peer-to-peer network game engine, is able to execute arbitrary code received from the p2p game network it is connected to without any security checks.
The old stable distribution (woody) does not contain py2play packages.
For the stable distribution (sarge) this problem has been fixed in version 0.1.7-1sarge1.
For the unstable distribution (sid) this problem has been fixed in version 0.1.8-1.
We recommend that you upgrade your py2play package.
- Fixed in:
-
Debian GNU/Linux 3.1 (sarge)
- Source:
- http://security.debian.org/pool/updates/main/p/py2play/py2play_0.1.7-1sarge1.dsc
- http://security.debian.org/pool/updates/main/p/py2play/py2play_0.1.7-1sarge1.diff.gz
- http://security.debian.org/pool/updates/main/p/py2play/py2play_0.1.7.orig.tar.gz
- http://security.debian.org/pool/updates/main/p/py2play/py2play_0.1.7-1sarge1.diff.gz
- Architecture-independent component:
- http://security.debian.org/pool/updates/main/p/py2play/python-2play_0.1.7-1sarge1_all.deb
MD5 checksums of the listed files are available in the original advisory.