Candidate: CVE-2018-1999023 PublicDate: 2018-07-23 16:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1999023 https://gist.github.com/shikadiqueen/45951ddc981cf8e0d9a74e4b30400380 Description: The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can result in code execution outside the sandbox. This attack appear to be exploitable via Loading specially-crafted saved games, networked games, replays, and player content. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_wesnoth-1.14: upstream_wesnoth-1.14: released (1:1.14.4-1) precise/esm_wesnoth-1.14: DNE trusty_wesnoth-1.14: DNE trusty/esm_wesnoth-1.14: DNE xenial_wesnoth-1.14: DNE bionic_wesnoth-1.14: DNE cosmic_wesnoth-1.14: not-affected (1:1.14.4-1) disco_wesnoth-1.14: not-affected (1:1.14.4-1) eoan_wesnoth-1.14: not-affected (1:1.14.4-1) focal_wesnoth-1.14: not-affected (1:1.14.4-1) groovy_wesnoth-1.14: not-affected (1:1.14.4-1) hirsute_wesnoth-1.14: not-affected (1:1.14.4-1) impish_wesnoth-1.14: not-affected (1:1.14.4-1) jammy_wesnoth-1.14: DNE devel_wesnoth-1.14: DNE Patches_wesnoth-1.12: upstream_wesnoth-1.12: released (1:1.12_1.12.6-1+deb9u1) precise/esm_wesnoth-1.12: DNE trusty_wesnoth-1.12: DNE trusty/esm_wesnoth-1.12: DNE xenial_wesnoth-1.12: ignored (end of standard support, was needed) bionic_wesnoth-1.12: released (1:1.12_1.12.6-1+deb9u1build0.18.04.1) cosmic_wesnoth-1.12: DNE disco_wesnoth-1.12: DNE eoan_wesnoth-1.12: DNE focal_wesnoth-1.12: DNE groovy_wesnoth-1.12: DNE hirsute_wesnoth-1.12: DNE impish_wesnoth-1.12: DNE jammy_wesnoth-1.12: DNE devel_wesnoth-1.12: DNE Patches_wesnoth-1.10: upstream_wesnoth-1.10: needed precise/esm_wesnoth-1.10: DNE trusty_wesnoth-1.10: ignored (reached end-of-life) trusty/esm_wesnoth-1.10: DNE (trusty was needed) xenial_wesnoth-1.10: DNE bionic_wesnoth-1.10: DNE cosmic_wesnoth-1.10: DNE disco_wesnoth-1.10: DNE eoan_wesnoth-1.10: DNE focal_wesnoth-1.10: DNE groovy_wesnoth-1.10: DNE hirsute_wesnoth-1.10: DNE impish_wesnoth-1.10: DNE jammy_wesnoth-1.10: DNE devel_wesnoth-1.10: DNE