Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-11722

Опубликовано: 12 апр. 2020
Источник: debian
EPSS Низкий

Описание

Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
crawlfixed2:0.25.0-1package
crawlno-dsabusterpackage
crawlno-dsastretchpackage
crawlno-dsajessiepackage

Примечания

  • https://dpmendenhall.blogspot.com/2020/03/dungeon-crawl-stone-soup.html

  • https://github.com/crawl/crawl/commit/768f60da87a3fa0b5561da5ade9309577c176d04

  • https://github.com/crawl/crawl/commit/fc522ff6eb1bbb85e3de60c60a45762571e48c28

EPSS

Процентиль: 87%
0.03645
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.

CVSS3: 9.8
nvd
больше 5 лет назад

Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.

suse-cvrf
больше 5 лет назад

Security update for crawl

github
больше 3 лет назад

Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.

EPSS

Процентиль: 87%
0.03645
Низкий