PT-2020-14076 · Freedroidrpg+1 · Freedroidrpg+1

Michał Dardas

·

Published

2020-06-23

·

Updated

2025-07-28

·

CVE-2020-14939

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreedroidRPG version 1.0rc2
Description An issue in the savestruct internal.c file allows saved game files, which are composed of Lua scripts, to be modified and execute arbitrary Lua code while loading, leading to arbitrary code execution.
Recommendations For FreedroidRPG version 1.0rc2, consider restricting the execution of Lua scripts from saved game files until a patch is available. As a temporary workaround, avoid loading saved game files from untrusted sources. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

CVE-2020-14939

Affected Products

Debian
Freedroidrpg