6.4

CVE-2011-1932

Directory traversal vulnerability in io/filesystem/filesystem.cc in Widelands before 15.1 might allow remote attackers to overwrite arbitrary files via . (dot) characters in a pathname that is used for a file transfer in an Internet game.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Widelands ≫ Widelands Version - Update build1
Widelands ≫ Widelands Version - Update build10
Widelands ≫ Widelands Version - Update build10_release_candidate
Widelands ≫ Widelands Version - Update build11
Widelands ≫ Widelands Version - Update build11_release_candidate
Widelands ≫ Widelands Version - Update build12
Widelands ≫ Widelands Version - Update build12_release_candidate
Widelands ≫ Widelands Version - Update build13
Widelands ≫ Widelands Version - Update build13_release_candidate
Widelands ≫ Widelands Version - Update build13_release_candidate2
Widelands ≫ Widelands Version - Update build14
Widelands ≫ Widelands Version - Update build14_release_candidate
Widelands ≫ Widelands Version - Update build2
Widelands ≫ Widelands Version - Update build3
Widelands ≫ Widelands Version - Update build4
Widelands ≫ Widelands Version - Update build5
Widelands ≫ Widelands Version - Update build6
Widelands ≫ Widelands Version - Update build7
Widelands ≫ Widelands Version - Update build8
Widelands ≫ Widelands Version - Update build9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.8% 0.761
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:N/I:P/A:P
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

http://bazaar.launchpad.net/~widelands-dev/widelands/build-15/revision/5021
Patch
Third Party Advisory
Release Notes
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=617960
Third Party Advisory
Issue Tracking