CVE-2015-5070
published 2017-09-26CVE-2015-5070: The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and…
PriorityP412low3.1CVSS 3.0
AVNACHPRLUINSUCLINAN
EPSS
1.38%
69.1th percentile
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is used, allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-5069.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| wesnoth | battle_for_wesnoth | <= 1.12.2 | — |
| wesnoth | battle_for_wesnoth | — | — |
CVSS provenance
nvdv3.03.1LOWCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5070 CVE-2015-5069 wesnoth: authentication information disclosure [epel-6]
bugzilla·2015-06-26·CVSS 4.3
CVE-2015-5070 [MEDIUM] CVE-2015-5070 CVE-2015-5069 wesnoth: authentication information disclosure [epel-6]
CVE-2015-5070 CVE-2015-5069 wesnoth: authentication information disclosure [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-6 tracking bug for wesnoth: see blocks b
Bugzilla
CVE-2015-5069 CVE-2015-5070 wesnoth: authentication information disclosure
bugzilla·2015-06-26·CVSS 4.3
CVE-2015-5069 [MEDIUM] CVE-2015-5069 CVE-2015-5070 wesnoth: authentication information disclosure
CVE-2015-5069 CVE-2015-5070 wesnoth: authentication information disclosure
Quoting from http://www.openwall.com/lists/oss-security/2015/06/25/2
"Wesnoth implements a text preprocessing language that is used in conjunction
with its own game scripting language. It also has a built-in Lua interpreter
and API. Both the Lua API and the preprocessor make use of the same function
(filesystem::get_wml_location()) to resolve file paths so that only content
from the user's data directory can be read.
However, the function did not explicitly disallow files with the .pbl
extension. The contents of these files could thus be stored in saved game
files or even transmitted directly to other users in a networked game. Among
the information that's compromised is a user-defined passphrase used to
authentic
Bugzilla
CVE-2015-5070 CVE-2015-5069 wesnoth: authentication information disclosure [fedora-all]
bugzilla·2015-06-26·CVSS 4.3
CVE-2015-5070 [MEDIUM] CVE-2015-5070 CVE-2015-5069 wesnoth: authentication information disclosure [fedora-all]
CVE-2015-5070 CVE-2015-5069 wesnoth: authentication information disclosure [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2015-5070 CVE-2015-5069 wesnoth: authentication information disclosure [epel-5]
bugzilla·2015-06-26·CVSS 4.3
CVE-2015-5070 [MEDIUM] CVE-2015-5070 CVE-2015-5069 wesnoth: authentication information disclosure [epel-5]
CVE-2015-5070 CVE-2015-5069 wesnoth: authentication information disclosure [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-5 tracking bug for wesnoth: see blocks b
http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161722.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-July/161752.htmlhttp://www.openwall.com/lists/oss-security/2015/06/25/12http://www.securityfocus.com/bid/75425https://bugzilla.redhat.com/show_bug.cgi?id=1236010https://github.com/wesnoth/wesnoth/commit/b2738ffb2fdd2550ececb74f76f75583c43c8b59https://github.com/wesnoth/wesnoth/releases/tag/1.12.4https://github.com/wesnoth/wesnoth/releases/tag/1.13.1https://gna.org/bugs/?23504http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161722.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-July/161752.htmlhttp://www.openwall.com/lists/oss-security/2015/06/25/12http://www.securityfocus.com/bid/75425https://bugzilla.redhat.com/show_bug.cgi?id=1236010https://github.com/wesnoth/wesnoth/commit/b2738ffb2fdd2550ececb74f76f75583c43c8b59https://github.com/wesnoth/wesnoth/releases/tag/1.12.4https://github.com/wesnoth/wesnoth/releases/tag/1.13.1https://gna.org/bugs/?23504
2017-09-26
Published