CVE-2015-5070
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is used, allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-5069.
La función (1) filesystem::get_wml_location en filesystem.cpp y la función (2) is_legal_file en filesystem_boost.cpp en Battle for Wesnoth en versiones anteriores a la 1.12.4 y las versiones 1.13.x anteriores a 1.13.1, cuando se usa un sistema de archivos no sensible a mayúsculas/minúsculas, permiten que los atacantes remotos obtengan información sensible mediante vectores relacionados con la inclusión de archivos .pbl desde WML. NOTA: Esta vulnerabilidad existe debido a una solución incompleta para CVE-2015-5069.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-06-25 CVE Reserved
- 2017-09-26 CVE Published
- 2023-05-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/75425 | Third Party Advisory | |
https://github.com/wesnoth/wesnoth/releases/tag/1.12.4 | Release Notes | |
https://github.com/wesnoth/wesnoth/releases/tag/1.13.1 | Release Notes | |
https://gna.org/bugs/?23504 | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.openwall.com/lists/oss-security/2015/06/25/12 | 2017-10-10 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1236010 | 2017-10-10 | |
https://github.com/wesnoth/wesnoth/commit/b2738ffb2fdd2550ececb74f76f75583c43c8b59 | 2017-10-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wesnoth Search vendor "Wesnoth" | Battle For Wesnoth Search vendor "Wesnoth" for product "Battle For Wesnoth" | <= 1.12.2 Search vendor "Wesnoth" for product "Battle For Wesnoth" and version " <= 1.12.2" | - |
Affected
| ||||||
Wesnoth Search vendor "Wesnoth" | Battle For Wesnoth Search vendor "Wesnoth" for product "Battle For Wesnoth" | 1.13.0 Search vendor "Wesnoth" for product "Battle For Wesnoth" and version "1.13.0" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 21 Search vendor "Fedoraproject" for product "Fedora" and version "21" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 22 Search vendor "Fedoraproject" for product "Fedora" and version "22" | - |
Affected
|