| Name | CVE-2020-14939 |
| Description | An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts that recover a game's state. A file can be modified to put any Lua code inside, leading to arbitrary code execution while loading. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| Debian Bugs | 964197 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| freedroidrpg (PTS) | bullseye | 0.16.1-6 | vulnerable |
| sid, bookworm | 1.0-1 | fixed |
The information below is based on the following data on fixed versions.
Notes
[bullseye] - freedroidrpg <no-dsa> (Minor issue)
[buster] - freedroidrpg <no-dsa> (Minor issue)
[stretch] - freedroidrpg <no-dsa> (Minor issue)
[jessie] - freedroidrpg <end-of-life> (games are not supported)
https://bugs.freedroid.org/b/issue953
https://bugs.freedroid.org/b/issue967
https://logicaltrust.net/blog/2020/02/freedroid.html