Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1000224

Опубликовано: 20 авг. 2018
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Средний

Описание

Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison, wrong buffer size chackes, integer overflow, missing padding initialization vulnerability in (De)Serialization functions (core/io/marshalls.cpp) that can result in DoS (packet of death), possible leak of uninitialized memory. This attack appear to be exploitable via A malformed packet is received over the network by a Godot application that uses built-in serialization (e.g. game server, or game client). Could be triggered by multiplayer opponent. This vulnerability appears to have been fixed in 2.1.5, 3.0.6, master branch after commit feaf03421dda0213382b51aff07bd5a96b29487b.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:godotengine:godot:*:*:*:*:*:*:*:*
Версия до 2.1.5 (исключая)
cpe:2.3:a:godotengine:godot:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.0.6 (исключая)

EPSS

Процентиль: 94%
0.13162
Средний

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-131

Связанные уязвимости

CVSS3: 7.5
debian
больше 7 лет назад

Godot Engine version All versions prior to 2.1.5, all 3.0 versions pri ...

CVSS3: 7.5
github
больше 3 лет назад

Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison, wrong buffer size chackes, integer overflow, missing padding initialization vulnerability in (De)Serialization functions (core/io/marshalls.cpp) that can result in DoS (packet of death), possible leak of uninitialized memory. This attack appear to be exploitable via A malformed packet is received over the network by a Godot application that uses built-in serialization (e.g. game server, or game client). Could be triggered by multiplayer opponent. This vulnerability appears to have been fixed in 2.1.5, 3.0.6, master branch after commit feaf03421dda0213382b51aff07bd5a96b29487b.

EPSS

Процентиль: 94%
0.13162
Средний

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-131