FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-12-02 20:06:50 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
2a8b7d21-1ecc-11e5-a4a5-002590263bf5wesnoth -- disclosure of .pbl files with lowercase, uppercase, and mixed-case extension

Ignacio R. Morelle reports:

As mentioned in the Wesnoth 1.12.4 and Wesnoth 1.13.1 release announcements, a security vulnerability targeting add-on authors was found (bug #23504) which allowed a malicious user to obtain add-on server passphrases from the client's .pbl files and transmit them over the network, or store them in saved game files intended to be shared by the victim. This vulnerability affects all existing releases up to and including versions 1.12.2 and 1.13.0. Additionally, version 1.12.3 included only a partial fix that failed to guard users against attempts to read from .pbl files with an uppercase or mixed-case extension. CVE-2015-5069 and CVE-2015-5070 have been assigned to the vulnerability affecting .pbl files with a lowercase extension, and .pbl files with an uppercase or mixed-case extension, respectively.


Discovery 2015-06-28
Entry 2015-07-01
wesnoth
< 1.12.4,1

CVE-2015-5069
CVE-2015-5070
http://forums.wesnoth.org/viewtopic.php?t=42776
http://forums.wesnoth.org/viewtopic.php?t=42775
bad59128-c188-11e8-9d40-f0def10dca57wesnoth -- Code Injection vulnerability

shadowm reports:

A severe bug was found in the game client which could allow a malicious user to execute arbitrary code through the Lua engine by using specially-crafted code in add-ons, saves, replays, or networked games. This issue affects all platforms and all existing releases since Wesnoth version 1.7.0. Users of all previous version should upgrade immediately.


Discovery 2018-07-14
Entry 2018-09-26
wesnoth
>= 1.7.0 lt 1.14.4,1

CVE-2018-1999023
https://gist.github.com/shikadiqueen/45951ddc981cf8e0d9a74e4b30400380