CVE-2018-1000224
Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison, wrong buffer size chackes, integer overflow, missing padding initialization vulnerability in (De)Serialization functions…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.79%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison, wrong buffer size chackes, integer overflow, missing padding initialization vulnerability in (De)Serialization functions (core/io/marshalls.cpp) that can result in DoS (packet of death), possible leak of uninitialized memory. This attack appear to be exploitable via A malformed packet is received over the network by a Godot application that uses built-in serialization (e.g. game server, or game client). Could be triggered by multiplayer opponent. This vulnerability appears to have been fixed in 2.1.5, 3.0.6, master branch after commit feaf03421dda0213382b51aff07bd5a96b29487b.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 3.79% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-131, CWE-190, CWE-681, CWE-908, CWE-909
- Affected
- godotengine/godot
- Source
- cve@mitre.org
References
- https://github.com/godotengine/godot/issues/20558Exploit, Issue Tracking, Patch, Third Party Advisory
- https://godotengine.org/article/maintenance-release-godot-2-1-5Vendor Advisory
- https://godotengine.org/article/maintenance-release-godot-3-0-6Vendor Advisory
- https://github.com/godotengine/godot/issues/20558Exploit, Issue Tracking, Patch, Third Party Advisory
- https://godotengine.org/article/maintenance-release-godot-2-1-5Vendor Advisory
- https://godotengine.org/article/maintenance-release-godot-3-0-6Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.