In Teeworlds 0.7.2, there is a failed bounds check in CDataFileReader::GetData() and CDataFileReader::ReplaceData() and related functions in engine/shared/datafile.cpp that can lead to an arbitrary free and out-of-bounds pointer write, possibly resulting in remote code execution.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.7.2-5", "binary_name": "teeworlds" }, { "binary_version": "0.7.2-5", "binary_name": "teeworlds-data" }, { "binary_version": "0.7.2-5", "binary_name": "teeworlds-dbgsym" }, { "binary_version": "0.7.2-5", "binary_name": "teeworlds-server" }, { "binary_version": "0.7.2-5", "binary_name": "teeworlds-server-dbgsym" } ] }