DEBIAN-CVE-2025-14308

Source
https://security-tracker.debian.org/tracker/CVE-2025-14308
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-14308.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2025-14308
Upstream
Published
2025-12-09T16:17:38Z
Modified
2026-09-01T20:05:41Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method fails to properly validate the length of data being written, allowing attackers to cause an overflow, potentially leading to buffer overflows and arbitrary code execution. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the data length, leading to potential unauthorized code execution.

References

Affected packages

Debian:12 / robocode

Package

Name
robocode
Purl
pkg:deb/debian/robocode?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.9.3.9-3
1.9.3.9-4
1.9.3.9-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-14308.json"

Debian:13 / robocode

Package

Name
robocode
Purl
pkg:deb/debian/robocode?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.9.3.9-4
1.9.3.9-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-14308.json"

Debian:14 / robocode

Package

Name
robocode
Purl
pkg:deb/debian/robocode?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.9.3.9-4
1.9.3.9-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-14308.json"