Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-15007

Опубликовано: 24 июн. 2020
Источник: debian
EPSS Низкий

Описание

A buffer overflow in the M_LoadDefaults function in m_misc.c in id Tech 1 (aka Doom engine) allows arbitrary code execution via an unsafe usage of fscanf, because it does not limit the number of characters to be read in a format argument.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rbdoom3bfgunfixedpackage

Примечания

  • https://github.com/AXDOOMER/doom-vanille/commit/8a6d9a02fa991a91ff90ccdc73b5ceabaa6cb9ec

  • Problematic code not built

EPSS

Процентиль: 83%
0.01995
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

A buffer overflow in the M_LoadDefaults function in m_misc.c in id Tech 1 (aka Doom engine) allows arbitrary code execution via an unsafe usage of fscanf, because it does not limit the number of characters to be read in a format argument.

CVSS3: 9.8
nvd
больше 5 лет назад

A buffer overflow in the M_LoadDefaults function in m_misc.c in id Tech 1 (aka Doom engine) allows arbitrary code execution via an unsafe usage of fscanf, because it does not limit the number of characters to be read in a format argument.

CVSS3: 9.8
github
больше 3 лет назад

A buffer overflow in the M_LoadDefaults function in m_misc.c in id Tech 1 (aka Doom engine) allows arbitrary code execution via an unsafe usage of fscanf, because it does not limit the number of characters to be read in a format argument.

EPSS

Процентиль: 83%
0.01995
Низкий