7.8
CVE-2020-12066
- EPSS 2.96%
- Veröffentlicht 22.04.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:59:12
- Erkennungen
CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opensuse ≫ Backports Sle Version 15.0 Update sp1
Fedoraproject ≫ Fedora Version 30
Debian ≫ Debian Linux Version 10.0
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.96% | 0.854 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00044.html
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00045.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AVYG7CCPS5F3OPOQMJKVNXTQ7BXSEX2V/
https://github.com/teeworlds/teeworlds/commit/c68402fa7e279d42886d5951d1ea8ac2facc1ea5
https://usn.ubuntu.com/4553-1/
https://www.debian.org/security/2020/dsa-4763
https://www.teeworlds.com/forum/viewtopic.php?id=14785