PT-2010-4025 · Freeciv · Freeciv
Moritz Muehlenhoff
·
Publicado
2010-07-07
·
Atualizado
2021-06-30
·
CVE-2010-2445
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
freeciv versions 2.2 through 2.2.1 and versions 2.3 through 2.3.0, but not including 2.3.0
Description
The issue allows attackers to read arbitrary files or execute arbitrary commands via a scenario that contains Lua functionality. This is related to various Lua modules or functions, including
os, io, package, dofile, loadfile, loadlib, module, and require.Recommendations
For freeciv versions 2.2 through 2.2.1, update to version 2.2.1 or later.
For freeciv versions 2.3 through 2.3.0, but not including 2.3.0, update to version 2.3.0 or later.
Correção
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Freeciv