Freeciv Lua Runtime Environment Remote Command Execution Vulnerability
BID:40598
Info
Freeciv Lua Runtime Environment Remote Command Execution Vulnerability
| Bugtraq ID: | 40598 |
| Class: | Unknown |
| CVE: |
CVE-2010-2445 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 07 2010 12:00AM |
| Updated: | Apr 13 2015 09:23PM |
| Credit: | Ulrik Sverdrup |
| Vulnerable: |
Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 Gentoo Linux Freeciv Freeciv 2.2 Freeciv Freeciv 2.1 beta1 Freeciv Freeciv 2.0.8 Freeciv Freeciv 2.0.7 Freeciv Freeciv 2.0.4 Freeciv Freeciv 2.0.1 Freeciv Freeciv 2.0 beta8 |
| Not Vulnerable: |
Freeciv Freeciv 2.2.1 |
Discussion
Freeciv Lua Runtime Environment Remote Command Execution Vulnerability
Freeciv is prone to a remote command-execution vulnerability that exists in the Lua runtime environment because the software fails to properly handle specially crafted 'saved game' or 'scenario' files.
An attacker could exploit this issue by enticing a victim to open a file.
Successful exploits would allow the attacker to execute arbitrary commands within the context of the affected application.
Versions prior to Freeciv 2.2.1 are vulnerable.
Freeciv is prone to a remote command-execution vulnerability that exists in the Lua runtime environment because the software fails to properly handle specially crafted 'saved game' or 'scenario' files.
An attacker could exploit this issue by enticing a victim to open a file.
Successful exploits would allow the attacker to execute arbitrary commands within the context of the affected application.
Versions prior to Freeciv 2.2.1 are vulnerable.
Exploit / POC
Freeciv Lua Runtime Environment Remote Command Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Freeciv Lua Runtime Environment Remote Command Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2010.0 x86_64
Mandriva Linux Mandrake 2010.1 x86_64
Mandriva Linux Mandrake 2010.1
Mandriva Linux Mandrake 2010.0
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2010.0 x86_64
-
Mandriva freeciv-client-2.2.1-0.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva freeciv-data-2.2.1-0.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva freeciv-server-2.2.1-0.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2010.1 x86_64
-
Mandriva freeciv-client-2.2.1-0.1mdv2010.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva freeciv-data-2.2.1-0.1mdv2010.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva freeciv-server-2.2.1-0.1mdv2010.1.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2010.1
-
Mandriva freeciv-client-2.2.1-0.1mdv2010.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva freeciv-data-2.2.1-0.1mdv2010.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva freeciv-server-2.2.1-0.1mdv2010.1.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2010.0
-
Mandriva freeciv-client-2.2.1-0.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva freeciv-data-2.2.1-0.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva freeciv-server-2.2.1-0.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/
References
Freeciv Lua Runtime Environment Remote Command Execution Vulnerability
References:
References:
- bug #15624: [RFC] scripting: Sandbox Lua scripts [Remove unsafe functionality] (Ulrik Sverdrup)
- Freeciv Changelog (Freeciv)