PT-2020-14107 · Chocolate Doom Team+2 · Chocolate Doom+2
Michał Dardas
·
Published
2020-06-22
·
Updated
2023-01-27
·
CVE-2020-14983
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Chocolate Doom version 3.0.0
Crispy Doom version 5.8.0
Description
The issue arises from the server's failure to validate the user-controlled
num players value, resulting in a buffer overflow. This allows a malicious user to overwrite the server's stack.Recommendations
For Chocolate Doom version 3.0.0, update to a version that includes input validation for the
num players value to prevent buffer overflows.
For Crispy Doom version 5.8.0, apply a patch or update that properly validates user-controlled input to prevent stack overwrites.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chocolate Doom
Crispy Doom
Suse