In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file.
{ "availability": "No subscription required", "ubuntu_priority": "negligible", "binaries": [ { "binary_version": "6.2.7-1", "binary_name": "gnuchess" }, { "binary_version": "6.2.7-1", "binary_name": "gnuchess-dbgsym" } ], "priority_reason": "This is neutralized via building with hardening flags. No real impact." }
{ "availability": "No subscription required", "ubuntu_priority": "negligible", "binaries": [ { "binary_version": "6.2.7-1", "binary_name": "gnuchess" }, { "binary_version": "6.2.7-1", "binary_name": "gnuchess-dbgsym" } ], "priority_reason": "This is neutralized via building with hardening flags. No real impact." }