The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading to a buffer overflow. A malicious user can overwrite the server's stack.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-14983.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "sle-15-sp1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.2"
}
]
}
]