CVE-2021-43518
Summary
| CVE | CVE-2021-43518 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-15 15:15:00 UTC |
| Updated | 2023-11-07 03:39:00 UTC |
| Description | Teeworlds up to and including 0.7.5 is vulnerable to Buffer Overflow. A map parser does not validate m_Channels value coming from a map file, leading to a buffer overflow. A malicious server may offer a specially crafted map that will overwrite client's stack causing denial of service or code execution. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 35 Update: teeworlds-0.7.5-10.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Fuzzing game map parsers, part 1 - Teeworlds – mmmds's blog |
MISC |
mmmds.pl |
|
| [SECURITY] Fedora 36 Update: teeworlds-0.7.5-10.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: teeworlds-0.7.5-10.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Stack buffer overflow (write) while loading map in CMapLayers::LoadEnvPoints, maplayers.cpp:184 · Issue #2981 · teeworlds/teeworlds · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 35 Update: teeworlds-0.7.5-10.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 184332 Debian Security Update for teeworlds (CVE-2021-43518)
- 283017 Fedora Security Update for teeworlds (FEDORA-2022-f446c92b48)
- 283018 Fedora Security Update for teeworlds (FEDORA-2022-f281321e55)
- 690810 Free Berkeley Software Distribution (FreeBSD) Security Update for teeworlds (5aaf534c-a069-11ec-acdc-14dae9d5a9d2)