CVE-2015-5069

EUVD-2015-5085
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
Affected Products (NVD)
VendorProductVersion
wesnothbattle_for_wesnoth
𝑥
≤ 1.12.2
wesnothbattle_for_wesnoth
1.13.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
wesnoth-1.10
artful
dne
bionic
dne
cosmic
dne
disco
dne
precise
ignored
trusty
dne
utopic
ignored
vivid
ignored
wily
dne
xenial
dne
yakkety
dne
zesty
dne
wesnoth-1.12
artful
not-affected
bionic
not-affected
cosmic
dne
disco
dne
precise
dne
trusty
dne
utopic
dne
vivid
ignored
wily
ignored
xenial
not-affected
yakkety
ignored
zesty
ignored