2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2015-0844" ,
"sourceIdentifier" : "security@debian.org" ,
"published" : "2015-04-14T18:59:03.997" ,
2024-11-22 23:14:22 +00:00
"lastModified" : "2024-11-21T02:23:50.500" ,
"vulnStatus" : "Modified" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "The WML/Lua API in Battle for Wesnoth 1.7.x through 1.11.x and 1.12.x before 1.12.2 allows remote attackers to read arbitrary files via a crafted (1) campaign or (2) map file."
} ,
{
"lang" : "es" ,
"value" : "La API WML/Lua en Battle for Wesnoth 1.7.x hasta 1.11.x y 1.12.x anterior a 1.12.2 permite a atacantes remotos leer ficheros arbitrarios a trav\u00e9s de un fichero manipulado de (1) campa\u00f1as o (2) mapas."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N" ,
2024-11-22 23:14:22 +00:00
"baseScore" : 5.0 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "NONE" ,
2024-11-22 23:14:22 +00:00
"availabilityImpact" : "NONE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 10.0 ,
"impactScore" : 2.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-200"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BF13F213-4540-47F5-80DD-84593E9EBD0E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A9696A32-5E4A-4C76-987F-F0102FF42E82"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "27E88A68-F1E0-4F2E-91EF-21093D6B47EC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6D6A1217-69FD-48D1-9F70-052904BC7C2F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4A2B104E-F7FC-4C6A-81C3-841C9BF99B9A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E882D4E0-6D6F-4A24-B0F3-24801E6BBFE0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "61B0409E-C8B1-4B09-A322-CFB14DDC2194"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "51C25161-88E6-4F09-8AE7-F35D4F42F040"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.8:beta1:*:*:*:*:*:*" ,
"matchCriteriaId" : "D2DDB230-BE76-475A-908C-FE1ACA269FD9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.9:beta2:*:*:*:*:*:*" ,
"matchCriteriaId" : "F943B300-18EC-430F-8F5B-90B7CD7093B5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.10-1.8:beta3:*:*:*:*:*:*" ,
"matchCriteriaId" : "11828BCA-C131-404C-BB2E-D4E5D16614DC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.11-1.8:beta4:*:*:*:*:*:*" ,
"matchCriteriaId" : "BA03771F-E0B0-47C2-BA0E-58D42B6A8EB3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.12-1.8:beta5:*:*:*:*:*:*" ,
"matchCriteriaId" : "D16A703C-45FF-4BE2-ADD9-B4A3ADF978ED"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.13-1.8:beta6:*:*:*:*:*:*" ,
"matchCriteriaId" : "F98A577E-52F0-4DC7-B506-5FE938765C01"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.14-1.8:beta7:*:*:*:*:*:*" ,
"matchCriteriaId" : "EDB893BE-E823-4723-8B21-F0225C0414AE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.15-1.8:rc1:*:*:*:*:*:*" ,
"matchCriteriaId" : "B30C9ED2-42E0-4920-958E-7862833186D8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.8.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0364DE0B-5D0A-4CE1-A2D4-278E8BCBE5AA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2B8185FD-A6C1-4815-85F2-F2976353ECCB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B782639E-9B83-4DD4-B5FB-B8031D171D06"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D1CE1D9D-3EFB-49E6-AED2-E99F732C1B61"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E08BA385-0C53-4CDB-A629-6E10BD48DBDE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3A942086-4CD5-4611-AD11-BDECA9F93090"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C3C642DE-3CC0-455F-A081-6821169467E2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D2BA4234-9099-4ED3-8BC2-D35064BDFBAD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A53325FD-882C-4BBC-8108-89F6F6A1C722"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3BDC7ABF-5FBF-4C73-BBFF-A679AE1DFB64"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CA5370C0-38AE-444F-B094-A4ED3B3D9CA3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.10:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BB972038-14B4-44F1-BC8A-FE8929BCAD8A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.11:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "05468C9A-C2C7-4208-8F62-A75678163C4F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.12:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "00B8D4D7-811E-4BD5-80BE-5E9858AD561D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.13:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F8E839AC-969A-4AEA-BF7D-76022B1DCAD9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.14:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "42AAB37D-9D5D-4791-80C5-3466C22808F6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.10.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C96EB1D7-8B33-4703-B7FB-E36D4B52DA04"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "213000CD-0CB8-4B3A-8986-E5F59C3B7A35"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8C09C0EC-21B9-4DA6-8211-55AD0E5EC806"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "45596E57-63A1-4263-82B0-3155ED28C01C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0F901384-0320-45E3-8652-F739AC85441F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8A1F8E08-8EE6-4892-8F5B-127E4E30BB4A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EA67E987-7D64-4815-ACA1-7F10417771B4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7E5F626E-D004-4705-BC78-A99F5B2BC192"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0A3943AD-A78A-430E-AE93-D4ED7BA46488"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D6F385B2-B4F5-4306-8BD2-3E0534E6D8D5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "54405EE3-1488-4F1F-827D-380D0CBC1A59"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.10:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8528F043-B24F-49ED-B7F0-1DACCEB3F095"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.11:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3F716A83-88BB-4161-ABAC-99D67598CD53"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.12:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "316912B3-3C0C-4FE0-BBC7-8072EB1254E4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.13:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CB25DCDF-0D68-4049-B347-E54D87A889BE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.14:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E8468322-92DC-467A-9FF5-8A7AB95EF3FD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.15:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B8F568E2-00C9-47FD-A9B1-ABFEA452D7AE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.16:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "759BEBDC-E5E3-4F59-AE4A-5A49BDC98FFB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.17:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5F017D7D-C8D6-43E5-90A3-152C9DCCC573"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.18:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E016A85C-245C-454E-8175-B74D872D7FD8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.19:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0AA23A88-683D-4769-A672-FFF4D08483F7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.12.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B1E1FD6B-8652-4776-BCFB-4552C7390BD6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wesnoth:battle_for_wesnoth:1.12.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F4FEA70E-498F-4CDB-8E84-FD41B6325C4F"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FF47C9F0-D8DA-4B55-89EB-9B2C9383ADB9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "56BDB5A0-0839-4A20-A003-B8CD56F48171"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "253C303A-E577-4488-93E6-68A8DD942C38"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://forums.wesnoth.org/viewtopic.php?t=41870" ,
"source" : "security@debian.org" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://forums.wesnoth.org/viewtopic.php?t=41872" ,
"source" : "security@debian.org" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155031.html" ,
"source" : "security@debian.org"
} ,
{
"url" : "http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155968.html" ,
"source" : "security@debian.org"
} ,
{
"url" : "http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156001.html" ,
"source" : "security@debian.org"
} ,
{
"url" : "http://www.debian.org/security/2015/dsa-3218" ,
"source" : "security@debian.org"
2024-11-22 23:14:22 +00:00
} ,
{
"url" : "http://forums.wesnoth.org/viewtopic.php?t=41870" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://forums.wesnoth.org/viewtopic.php?t=41872" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155031.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155968.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156001.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.debian.org/security/2015/dsa-3218" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2023-04-24 12:24:31 +02:00
}
]
}