CVE-2020-14938

unknown
Published — · Modified —
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk

Description

An issue was discovered in map.c in FreedroidRPG 1.0rc2. It assumes lengths of data sets read from saved game files. It copies data from a file into a fixed-size heap-allocated buffer without size verification, leading to a heap-based buffer overflow.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2020-14938 NameCVE-2020-14938 DescriptionAn issue was discovered in map.c in FreedroidRPG 1.0rc2. It assumes lengths of data sets read from saved game files. It copies data from a file into a fixed-size heap-allocated buffer without size verification, leading to a heap-based buffer overflow. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE…

CVE-2020-14938

NameCVE-2020-14938
DescriptionAn issue was discovered in map.c in FreedroidRPG 1.0rc2. It assumes lengths of data sets read from saved game files. It copies data from a file into a fixed-size heap-allocated buffer without size verification, leading to a heap-based buffer overflow.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs964197

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
freedroidrpg (PTS)bullseye0.16.1-6vulnerable
bookworm1.0-1fixed
sid1.0+ds-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
freedroidrpgsourcejessie(unfixed)end-of-life
freedroidrpgsource(unstable)1.0-1low964197

Notes

[bullseye] - freedroidrpg <no-dsa> (Minor issue)
[buster] - freedroidrpg <no-dsa> (Minor issue)
[stretch] - freedroidrpg <no-dsa> (Minor issue)
[jessie] - freedroidrpg <end-of-life> (games are not supported)
https://bugs.freedroid.org/b/issue952
https://bugs.freedroid.org/b/issue967
https://logicaltrust.net/blog/2020/02/freedroid.html

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[bullseye] - freedroidrpg <no-dsa> (Minor issue)[buster] - freedroidrpg <no-dsa> (Minor issue)[stretch] - freedroidrpg <no-dsa> (Minor issue)[jessie] - freedroidrpg <end-of-life> (games are not supported)https://bugs.freedroid.org/b/issue952https://bugs.freedroid.org/b/issue967https://logicaltrust.net/blog/2020/02/freedroid.html

OS impact

debian Debian Mixed 3 releases
VersionStatusFixed in
sid Fixed 1.0-1
bullseye Affected
bookworm Fixed 1.0-1

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.