CVE-2018-1999023
high
CVSS v3
—
CVSS v2
—
VIR risk
8.0
Description
The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can result in code execution outside the sandbox. This attack appear to be exploitable via Loading specially-crafted saved games, networked games, replays, and player content.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2018-1999023
Vendor advisory: arch — https://security.archlinux.org/ASA-201807-15
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | fixed | 1.14.4-1 | |
| debian | bullseye | fixed | 1:1.14.4-1 |
References
Verify integrity in audit chain (admin only). AS-IS.