Battle for Wesnoth WML Preprocessor Directory Traversal Vulnerability
BID:26626
Info
Battle for Wesnoth WML Preprocessor Directory Traversal Vulnerability
| Bugtraq ID: | 26626 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-5742 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2007 12:00AM |
| Updated: | Apr 13 2015 10:16PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Wesnoth Wesnoth 1.2.7 Wesnoth Wesnoth 1.2.6 Redhat Fedora 7 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
Wesnoth Wesnoth 1.2.8 |
Discussion
Battle for Wesnoth WML Preprocessor Directory Traversal Vulnerability
Battle for Wesnoth is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue may allow an attacker to access sensitive information that could aid in further attacks.
Versions prior to Battle for Wesnoth 1.2.8 are vulnerable.
Battle for Wesnoth is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue may allow an attacker to access sensitive information that could aid in further attacks.
Versions prior to Battle for Wesnoth 1.2.8 are vulnerable.
Exploit / POC
Battle for Wesnoth WML Preprocessor Directory Traversal Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Battle for Wesnoth WML Preprocessor Directory Traversal Vulnerability
Solution:
The vendor has released updates to address this issue. Contact the vendor for details on obtaining and applying the appropriate updates.
Wesnoth Wesnoth 1.2.6
Wesnoth Wesnoth 1.2.7
Solution:
The vendor has released updates to address this issue. Contact the vendor for details on obtaining and applying the appropriate updates.
Wesnoth Wesnoth 1.2.6
-
Wesnoth wesnoth-1.2.8.tar.bz2
http://downloads.sourceforge.net/wesnoth/wesnoth-1.2.8.tar.bz2?downloa d
Wesnoth Wesnoth 1.2.7
-
Wesnoth wesnoth-1.2.8.tar.bz2
http://downloads.sourceforge.net/wesnoth/wesnoth-1.2.8.tar.bz2?downloa d
References
Battle for Wesnoth WML Preprocessor Directory Traversal Vulnerability
References:
References:
- Wesnoth 1.2.8 Change Log (Wesnoth)
- Wesnoth Homepage (Wesnoth)