PT-2018-9391 · Godot+1 · Godot Engine+1

Fabio Alessandrelli

·

Published

2018-08-20

·

Updated

2020-08-24

·

CVE-2018-1000224

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Godot Engine versions prior to 2.1.5 Godot Engine versions 3.0 prior to 3.0.6
Description The issue is related to signed/unsigned comparison, wrong buffer size checks, integer overflow, and missing padding initialization in (De)Serialization functions. This can result in a Denial of Service (DoS) and possible leak of uninitialized memory. The attack can be triggered by a malformed packet received over the network by a Godot application that uses built-in serialization, such as a game server or game client, potentially by a multiplayer opponent.
Recommendations For Godot Engine versions prior to 2.1.5, update to version 2.1.5 or later. For Godot Engine versions 3.0 prior to 3.0.6, update to version 3.0.6 or later.

Exploit

Fix

DoS

Integer Overflow

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2018-2381
CVE-2018-1000224

Affected Products

Alt Linux
Godot Engine