CVE-2018-1000224

Source
https://cve.org/CVERecord?id=CVE-2018-1000224
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000224.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-1000224
Published
2018-08-20T20:29:01.597Z
Modified
2026-04-10T04:03:35.417906Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison, wrong buffer size chackes, integer overflow, missing padding initialization vulnerability in (De)Serialization functions (core/io/marshalls.cpp) that can result in DoS (packet of death), possible leak of uninitialized memory. This attack appear to be exploitable via A malformed packet is received over the network by a Godot application that uses built-in serialization (e.g. game server, or game client). Could be triggered by multiplayer opponent. This vulnerability appears to have been fixed in 2.1.5, 3.0.6, master branch after commit feaf03421dda0213382b51aff07bd5a96b29487b.

References

Affected packages

Git / github.com/godotengine/godot

Affected ranges

Type
GIT
Repo
https://github.com/godotengine/godot
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.1.5"
        },
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.0.6"
        }
    ]
}

Affected versions

2.*
2.0-stable
2.1-stable
2.1.1-stable
2.1.2-stable
2.1.3-stable
2.1.4-stable
3.*
3.0-stable
3.0.1-stable
3.0.2-stable
3.0.3-stable
3.0.4-stable
3.0.5-stable

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000224.json"