Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:58
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00037.html - | |
References | () https://dpmendenhall.blogspot.com/2020/03/dungeon-crawl-stone-soup.html - Patch, Third Party Advisory | |
References | () https://github.com/crawl/crawl/commit/768f60da87a3fa0b5561da5ade9309577c176d04 - Patch, Third Party Advisory | |
References | () https://github.com/crawl/crawl/commit/fc522ff6eb1bbb85e3de60c60a45762571e48c28 - Patch, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6QLPN635S7J3MUXLIHYK6MDAHEIASFYP/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XNXK7QE7EA7XSDDNOWX2A6MJNWOIYCTC/ - |
07 Nov 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2020-04-12 19:15
Updated : 2024-11-21 04:58
NVD link : CVE-2020-11722
Mitre link : CVE-2020-11722
CVE.ORG link : CVE-2020-11722
JSON object : View
Products Affected
dungeon_crawl_stone_soup_project
- dungeon_crawl_stone_soup
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type