CVE-2018-1999023
The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can result in code execution outside the sandbox.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.72%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can result in code execution outside the sandbox. This attack appear to be exploitable via Loading specially-crafted saved games, networked games, replays, and player content.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 1.72% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- wesnoth/the battle for wesnoth
- Source
- cve@mitre.org
References
- https://gist.github.com/shikadiqueen/45951ddc981cf8e0d9a74e4b30400380Patch, Third Party Advisory
- https://gist.github.com/shikadiqueen/45951ddc981cf8e0d9a74e4b30400380Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.