PT-2010-4025 · Freeciv · Freeciv
Moritz Muehlenhoff
·
Published
2010-07-07
·
Updated
2021-06-30
·
CVE-2010-2445
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
freeciv versions 2.2 through 2.2.1 and versions 2.3 through 2.3.0, but not including 2.3.0
Description
The issue allows attackers to read arbitrary files or execute arbitrary commands via a scenario that contains Lua functionality. This is related to various Lua modules or functions, including
os, io, package, dofile, loadfile, loadlib, module, and require.Recommendations
For freeciv versions 2.2 through 2.2.1, update to version 2.2.1 or later.
For freeciv versions 2.3 through 2.3.0, but not including 2.3.0, update to version 2.3.0 or later.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freeciv