CVE-2018-1999023
23.07.2018, 16:29
The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can result in code execution outside the sandbox. This attack appear to be exploitable via Loading specially-crafted saved games, networked games, replays, and player content.
Vendor | Product | Version |
---|---|---|
wesnoth | the_battle_for_wesnoth | 1.7.0 ≤ 𝑥 ≤ 1.14.3 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
wesnoth-1.10 |
| ||||||||||||||||||||||||||
wesnoth-1.12 |
| ||||||||||||||||||||||||||
wesnoth-1.14 |
|