Vulnerability Description
Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dungeon Crawl Stone Soup Project | Dungeon Crawl Stone Soup | < 0.25 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00037.html
- https://dpmendenhall.blogspot.com/2020/03/dungeon-crawl-stone-soup.htmlPatchThird Party Advisory
- https://github.com/crawl/crawl/commit/768f60da87a3fa0b5561da5ade9309577c176d04PatchThird Party Advisory
- https://github.com/crawl/crawl/commit/fc522ff6eb1bbb85e3de60c60a45762571e48c28PatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00037.html
- https://dpmendenhall.blogspot.com/2020/03/dungeon-crawl-stone-soup.htmlPatchThird Party Advisory
- https://github.com/crawl/crawl/commit/768f60da87a3fa0b5561da5ade9309577c176d04PatchThird Party Advisory
- https://github.com/crawl/crawl/commit/fc522ff6eb1bbb85e3de60c60a45762571e48c28PatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2020-11722?
CVE-2020-11722 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.
How severe is CVE-2020-11722?
CVE-2020-11722 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-11722?
Check the references section above for vendor advisories and patch information. Affected products include: Dungeon Crawl Stone Soup Project Dungeon Crawl Stone Soup.