Vulnerability Description
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wesnoth | Battle For Wesnoth | <= 1.12.2 |
| Fedoraproject | Fedora | 21 |
Related Weaknesses (CWE)
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161722.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161752.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2015/06/25/12Mailing ListPatchThird Party Advisory
- http://www.securityfocus.com/bid/75424Third Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1236010Issue TrackingThird Party AdvisoryVDB Entry
- https://github.com/wesnoth/wesnoth/commit/f8914468182e8d0a1551b430c0879ba236fe4dPatchThird Party Advisory
- https://github.com/wesnoth/wesnoth/releases/tag/1.12.3Release NotesThird Party Advisory
- https://github.com/wesnoth/wesnoth/releases/tag/1.13.1Release NotesThird Party Advisory
- https://gna.org/bugs/?23504Broken Link
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161722.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161752.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2015/06/25/12Mailing ListPatchThird Party Advisory
- http://www.securityfocus.com/bid/75424Third Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1236010Issue TrackingThird Party AdvisoryVDB Entry
- https://github.com/wesnoth/wesnoth/commit/f8914468182e8d0a1551b430c0879ba236fe4dPatchThird Party Advisory
FAQ
What is CVE-2015-5069?
CVE-2015-5069 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attacke...
How severe is CVE-2015-5069?
CVE-2015-5069 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-5069?
Check the references section above for vendor advisories and patch information. Affected products include: Wesnoth Battle For Wesnoth, Fedoraproject Fedora.