Описание
Security update for chocolate-doom
This update for chocolate-doom to version 3.0.1 fixes the following issues:
- CVE-2020-14983: Fixed a stack-based buffer overflow in the networking code (boo#1173595).
Список пакетов
openSUSE Leap 15.2
chocolate-doom-3.0.1-lp152.4.3.1
chocolate-doom-bash-completion-3.0.1-lp152.4.3.1
Ссылки
- E-Mail link for openSUSE-SU-2020:0939-1
- SUSE Security Ratings
- SUSE Bug 1173595
- SUSE CVE CVE-2020-14983 page
Описание
The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading to a buffer overflow. A malicious user can overwrite the server's stack.
Затронутые продукты
openSUSE Leap 15.2:chocolate-doom-3.0.1-lp152.4.3.1
openSUSE Leap 15.2:chocolate-doom-bash-completion-3.0.1-lp152.4.3.1
Ссылки
- CVE-2020-14983
- SUSE Bug 1173595