[Japanese]
|
JVNDB-2015-000123
|
NScripter vulnerable to buffer overflow
|
NScripter is a script engine to build and execute games. NScripter contains a buffer overflow vulnerability due to a flaw in processing save data.
Kusano Kazuhiko reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 6.8 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Medium
- Authentication: None
- Confidentiality Impact: Partial
- Integrity Impact: Partial
- Availability Impact: Partial
|
|
Naoki Takahashi
- NScripter prior to Ver3.00 and Games built using NScripter prior to Ver3.00
|
|
By processing a specially crafted save data, arbitrary code may be executed.
|
For developers using NScripter:
[Update and Rebuild the Game]
Update NScripter to the latest version according to the information provided by the developer and rebuild the games.
For users of the games built using NScripter:
[Update the Game]
Update the game to the latest version according to the information provided by each repsective game developer.
|
Naoki Takahashi
|
- Buffer Errors(CWE-119) [IPA Evaluation]
|
- CVE-2015-2991
|
- JVN : JVN#08494613
- National Vulnerability Database (NVD) : CVE-2015-2991
- IPA SECURITY ALERTS : Security Alert for Vulnerability in NScripter (JVN#08494613) (in Japanese)
|
- [2015/09/02]
Web page was published
[2015/09/09]
References : Content was added
|