PT-2020-14107 · Chocolate Doom Team+2 · Chocolate Doom+2

Michał Dardas

·

Published

2020-06-22

·

Updated

2023-01-27

·

CVE-2020-14983

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chocolate Doom version 3.0.0 Crispy Doom version 5.8.0
Description The issue arises from the server's failure to validate the user-controlled num players value, resulting in a buffer overflow. This allows a malicious user to overwrite the server's stack.
Recommendations For Chocolate Doom version 3.0.0, update to a version that includes input validation for the num players value to prevent buffer overflows. For Crispy Doom version 5.8.0, apply a patch or update that properly validates user-controlled input to prevent stack overwrites.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2020-14983
MGASA-2020-0302
OPENSUSE-SU-2020:0928-1
OPENSUSE-SU-2020:0939-1
OPENSUSE-SU-2020:0947-1
OPENSUSE-SU-2020_0928-1
OPENSUSE-SU-2020_0939-1
OPENSUSE-SU-2024:10680-1

Affected Products

Chocolate Doom
Crispy Doom
Suse