Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-1999023

Опубликовано: 23 июл. 2018
Источник: debian
EPSS Низкий

Описание

The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can result in code execution outside the sandbox. This attack appear to be exploitable via Loading specially-crafted saved games, networked games, replays, and player content.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wesnoth-1.14fixed1:1.14.4-1package
wesnoth-1.12removedpackage
wesnoth-1.12fixed1:1.12.6-1+deb9u1stretchpackage
wesnoth-1.10removedpackage
wesnoth-1.10end-of-lifejessiepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2018/07/20/1

  • https://github.com/wesnoth/wesnoth/commit/d911268a783467842d38eae7ac1630f1fea41318 (1.14.x)

EPSS

Процентиль: 75%
0.01724
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 8 лет назад

The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can result in code execution outside the sandbox. This attack appear to be exploitable via Loading specially-crafted saved games, networked games, replays, and player content.

CVSS3: 8.8
nvd
около 8 лет назад

The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can result in code execution outside the sandbox. This attack appear to be exploitable via Loading specially-crafted saved games, networked games, replays, and player content.

CVSS3: 8.8
msrc
около 2 лет назад

The Battle for Wesnoth Project contains a Code Injection that can result in code execution outside the sandbox

CVSS3: 8.8
github
около 4 лет назад

The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can result in code execution outside the sandbox. This attack appear to be exploitable via Loading specially-crafted saved games, networked games, replays, and player content.

EPSS

Процентиль: 75%
0.01724
Низкий