PT-2020-14075 · Freedroidrpg Team+1 · Freedroidrpg+1
Michał Dardas
·
Published
2020-06-23
·
Updated
2025-07-28
·
CVE-2020-14938
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FreedroidRPG version 1.0rc2
Description
The issue arises from the assumption of data set lengths read from saved game files in map.c. It leads to a heap-based buffer overflow due to the lack of size verification when copying data from a file into a fixed-size heap-allocated buffer.
Recommendations
For FreedroidRPG version 1.0rc2, consider restricting access to saved game files to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the affected map.c functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Freedroidrpg