In Teeworlds 0.7.2, there is an integer overflow in CDataFileReader::Open() in engine/shared/datafile.cpp that can lead to a buffer overflow and possibly remote code execution, because size-related multiplications are mishandled.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.7.2-5", "binary_name": "teeworlds" }, { "binary_version": "0.7.2-5", "binary_name": "teeworlds-data" }, { "binary_version": "0.7.2-5", "binary_name": "teeworlds-dbgsym" }, { "binary_version": "0.7.2-5", "binary_name": "teeworlds-server" }, { "binary_version": "0.7.2-5", "binary_name": "teeworlds-server-dbgsym" } ] }