Debian GNU/Linux Advisory: mah-jong

May 14, 2004, 02:29 (1 Talkback[s])

Debian Security Advisory DSA 503-1 Martin Schulze
May 13th, 2004

Package : mah-jong
Vulnerability : missing argument check
Problem-Type : remote
Debian-specific: no
CVE ID : CAN-2004-0458

A problem has been discovered in mah-jong, a variant of the original Mah-Jong game, that can be utilised to crash the game server after dereferencing a NULL pointer. This bug be exploited by any client that connects to the mah-jong server.

For the stable distribution (woody) this problem has been fixed in version 1.4-3.

For the unstable distribution (sid) this problem has been fixed in version 1.6.2-1.

We recommend that you upgrade your mah-jong package.

Debian GNU/Linux 3.0 alias woody

