MGASA-2015-0034

Source
https://advisories.mageia.org/MGASA-2015-0034.html
Import Source
https://advisories.mageia.org/MGASA-2015-0034.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0034
Published
2015-01-21T17:15:23Z
Modified
2026-04-16T04:28:45Z
Summary
Updated freeciv packages fix a security vulnerability
Details

Updated freeciv packages to latest bugfix version, also fixing security vulnerability

Freeciv 2.4.1 in Mageia 4 was built against an embedded version of lua 5.1, vulnerable to the following security issue:

A heap-based overflow vulnerability was found in the way Lua handles varargs functions with many fixed parameters called with few arguments, leading to application crashes or, potentially, arbitrary code execution (CVE-2014-5461, mga#14038).

As of this update, Freeciv is now built against the patched system version of lua 5.1.

This update also provides Freeciv 2.4.4, a maintenance release in the 2.4.x stable branch with numerous bug fixes and minor new features. See the referenced release notes for details.

References
Credits

Affected packages

Mageia:4 / freeciv

Package

Name
freeciv
Purl
pkg:rpm/mageia/freeciv?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.4-1.mga4

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2015-0034.json"