In Teeworlds 0.7.2, there is an integer overflow in CDataFileReader::Open() in engine/shared/datafile.cpp that can lead to a buffer overflow and possibly remote code execution, because size-related multiplications are mishandled.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "teeworlds", "binary_version": "0.7.2-5" }, { "binary_name": "teeworlds-data", "binary_version": "0.7.2-5" }, { "binary_name": "teeworlds-dbgsym", "binary_version": "0.7.2-5" }, { "binary_name": "teeworlds-server", "binary_version": "0.7.2-5" }, { "binary_name": "teeworlds-server-dbgsym", "binary_version": "0.7.2-5" } ] }