Candidate: CVE-2010-2445 PublicDate: 2010-07-08 12:54:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2445 Description: freeciv 2.2 before 2.2.1 and 2.3 before 2.3.0 allows attackers to read arbitrary files or execute arbitrary commands via a scenario that contains Lua functionality, related to the (1) os, (2) io, (3) package, (4) dofile, (5) loadfile, (6) loadlib, (7) module, and (8) require modules or functions. Ubuntu-Description: Notes: Bugs: http://gna.org/bugs/?15624 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_freeciv: upstream_freeciv: released (2.2.1,2.3.0) dapper_freeciv: ignored (reached end-of-life) hardy_freeciv: ignored (reached end-of-life) jaunty_freeciv: ignored (reached end-of-life) karmic_freeciv: ignored (reached end-of-life) lucid_freeciv: ignored (reached end-of-life) maverick_freeciv: ignored (reached end-of-life) natty_freeciv: ignored (reached end-of-life) oneiric_freeciv: ignored (reached end-of-life) precise_freeciv: ignored (reached end-of-life) precise/esm_freeciv: DNE (precise was needed) quantal_freeciv: ignored (reached end-of-life) raring_freeciv: ignored (reached end-of-life) saucy_freeciv: ignored (reached end-of-life) trusty_freeciv: not-affected (2.4.2-1) trusty/esm_freeciv: DNE (trusty was not-affected [2.4.2-1]) utopic_freeciv: ignored (reached end-of-life) vivid_freeciv: ignored (reached end-of-life) vivid/stable-phone-overlay_freeciv: DNE vivid/ubuntu-core_freeciv: DNE wily_freeciv: ignored (reached end-of-life) xenial_freeciv: not-affected (2.4.2-1) yakkety_freeciv: ignored (reached end-of-life) zesty_freeciv: ignored (reached end-of-life) artful_freeciv: ignored (reached end-of-life) bionic_freeciv: not-affected (2.4.2-1) cosmic_freeciv: not-affected (2.4.2-1) devel_freeciv: not-affected (2.4.2-1)