CVE-2011-4675

NameCVE-2011-4675
DescriptionThe pathname canonicalization functionality in io/filesystem/filesystem.cc in Widelands before 15.1 expands leading ~ (tilde) characters to home-directory pathnames but does not restrict use of these characters in strings received from the network, which might allow remote attackers to conduct absolute path traversal attacks and overwrite arbitrary files via a ~ in a pathname that is used for a file transfer in an Internet game, a different vulnerability than CVE-2011-1932.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
widelands (PTS)bullseye1:21-1fixed
bookworm2:1.1-3fixed
sid, trixie2:1.2.1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
widelandssource(unstable)1:15-3low

Notes

Nearly a duplicate of CVE-2011-1932.
CVE's SPLIT decision is unclear.

Search for package or bug name: Reporting problems