Описание
Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| crawl | fixed | 2:0.25.0-1 | package | |
| crawl | no-dsa | buster | package | |
| crawl | no-dsa | stretch | package | |
| crawl | no-dsa | jessie | package |
Примечания
https://dpmendenhall.blogspot.com/2020/03/dungeon-crawl-stone-soup.html
https://github.com/crawl/crawl/commit/768f60da87a3fa0b5561da5ade9309577c176d04
https://github.com/crawl/crawl/commit/fc522ff6eb1bbb85e3de60c60a45762571e48c28
EPSS
Связанные уязвимости
Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.
Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.
Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.
EPSS