CVE-2020-12066Improper Input Validation in Teeworlds

Severity
7.5HIGHNVD
EPSS
5.7%
top 9.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 22
Latest updateMay 24

Description

CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDteeworlds/teeworlds0.7.00.7.5
Debianteeworlds/teeworlds< 0.7.5-1+3
NVDopensuse/leap15.1

Also affects: Debian Linux 10.0, Fedora 30, Ubuntu Linux 20.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-733m-275p-p27q: CServer::SendMsg in engine/server/server2022-05-24
OSV
CVE-2020-12066: CServer::SendMsg in engine/server/server2020-04-22
CVEList
CVE-2020-12066: CServer::SendMsg in engine/server/server2020-04-22

📋Vendor Advisories

2
Ubuntu
Teeworlds vulnerability2020-09-28
Debian
CVE-2020-12066: teeworlds - CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 all...2020

💬Community

3
Bugzilla
CVE-2020-12066 teeworlds: allows an attacker force the server to repetitively shut down [fedora-all]2020-04-29
Bugzilla
CVE-2020-12066 teeworlds: allows an attacker force the server to repetitively shut down [epel-7]2020-04-29
Bugzilla
CVE-2020-12066 teeworlds: allows an attacker force the server to repetitively shut down2020-04-29
CVE-2020-12066 — Improper Input Validation in Teeworlds | cvebase