7.8

CVE-2020-12066

CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Teeworlds ≫ Teeworlds Version >= 0.7.0 < 0.7.5
Opensuse ≫ Backports Sle Version 15.0 Update sp1
Opensuse ≫ Leap Version 15.1
Fedoraproject ≫ Fedora Version 30
Debian ≫ Debian Linux Version 10.0
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.96% 0.854
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00044.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00045.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AVYG7CCPS5F3OPOQMJKVNXTQ7BXSEX2V/
https://github.com/teeworlds/teeworlds/commit/c68402fa7e279d42886d5951d1ea8ac2facc1ea5
Patch
Third Party Advisory
https://usn.ubuntu.com/4553-1/
Third Party Advisory
https://www.debian.org/security/2020/dsa-4763
Third Party Advisory
https://www.teeworlds.com/forum/viewtopic.php?id=14785
Vendor Advisory