Name | CVE-2020-14939 |
Description | An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts that recover a game's state. A file can be modified to put any Lua code inside, leading to arbitrary code execution while loading. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 964197 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
freedroidrpg (PTS) | buster | 0.16.1-4 | vulnerable |
bullseye | 0.16.1-6 | vulnerable | |
bookworm, sid | 1.0-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
freedroidrpg | source | jessie | (unfixed) | end-of-life | ||
freedroidrpg | source | (unstable) | 1.0-1 | low | 964197 |
[bullseye] - freedroidrpg <no-dsa> (Minor issue)
[buster] - freedroidrpg <no-dsa> (Minor issue)
[stretch] - freedroidrpg <no-dsa> (Minor issue)
[jessie] - freedroidrpg <end-of-life> (games are not supported)
https://bugs.freedroid.org/b/issue953
https://bugs.freedroid.org/b/issue967
https://logicaltrust.net/blog/2020/02/freedroid.html