The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can result in code execution outside the sandbox. This attack appear to be exploitable via Loading specially-crafted saved games, networked games, replays, and player content.
{
"binaries": [
{
"binary_name": "wesnoth",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-aoi",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-core",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-data",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-did",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-dm",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-dw",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-ei",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-httt",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-l",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-low",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-music",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-nr",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-server",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-sof",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-sotbe",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-thot",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-tools",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-trow",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-tsg",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-ttb",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-1.12-utbs",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-core",
"binary_version": "1:1.12.5-1"
},
{
"binary_name": "wesnoth-music",
"binary_version": "1:1.12.5-1"
}
]
}
{
"binaries": [
{
"binary_name": "wesnoth",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-aoi",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-core",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-data",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-did",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-dm",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-dw",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-ei",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-httt",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-l",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-low",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-music",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-nr",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-server",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-sof",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-sotbe",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-thot",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-tools",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-trow",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-tsg",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-ttb",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-1.12-utbs",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-core",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
},
{
"binary_name": "wesnoth-music",
"binary_version": "1:1.12.6-1+deb9u1build0.18.04.1"
}
],
"availability": "No subscription required"
}