Name | CVE-2020-14939 |
Description | An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts that recover a game's state. A file can be modified to put any Lua code inside, leading to arbitrary code execution while loading. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 964197 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
freedroidrpg (PTS) | bullseye | 0.16.1-6 | vulnerable |
| sid, bookworm | 1.0-1 | fixed |
The information below is based on the following data on fixed versions.
Notes
[bullseye] - freedroidrpg <no-dsa> (Minor issue)
[buster] - freedroidrpg <no-dsa> (Minor issue)
[stretch] - freedroidrpg <no-dsa> (Minor issue)
[jessie] - freedroidrpg <end-of-life> (games are not supported)
https://bugs.freedroid.org/b/issue953
https://bugs.freedroid.org/b/issue967
https://logicaltrust.net/blog/2020/02/freedroid.html