CVE-2020-15007
24.06.2020, 11:15
A buffer overflow in the M_LoadDefaults function in m_misc.c in id Tech 1 (aka Doom engine) allows arbitrary code execution via an unsafe usage of fscanf, because it does not limit the number of characters to be read in a format argument.
| Vendor | Product | Version |
|---|---|---|
| idsoftware | tech_1 | - |
| doom_vanille_project | doom_vanille | 𝑥 < 671 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References