| Summary: | chocolate-doom new security issue CVE-2020-14983 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | andrewsfarm, davidwhodgins, geiger.david68210, mageia, sysadmin-bugs |
| Version: | 7 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA7-64-OK | ||
| Source RPM: | chocolate-doom-3.0.0-3.mga7.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2020-07-07 22:51:07 CEST
No recent maintainer, so assigning this globally. Assignee:
bugsquad =>
pkg-bugs Advisory: ======================== Updated chocolate-doom package fixes security vulnerability: The server in Chocolate Doom 3.0.0 doesn't validate the user-controlled num_players value, leading to a buffer overflow. A malicious user can overwrite the server's stack (CVE-2020-14983). References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14983 https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00007.html ======================== Updated packages in core/updates_testing: ======================== chocolate-doom-3.0.1-1.mga7 from chocolate-doom-3.0.1-1.mga7.src.rpm Assignee:
pkg-bugs =>
qa-bugs Installed and tested without issues. After setting the keys to a sane configuration, played for about 30 minutes and a few levels from Doom, Doom2 and Dooms day of UAC. No problems found. $ uname -a Linux marte 5.6.14-desktop-2.mga7 #1 SMP Wed May 20 23:14:20 UTC 2020 x86_64 x86_64 x86_64 GNU/Linux $ rpm -qa | grep doom freedoom-0.11.3-1.mga7 chocolate-doom-3.0.1-1.mga7 Whiteboard:
(none) =>
MGA7-64-OK Validating. Advisory in Comment 3. Keywords:
(none) =>
validated_update
Dave Hodgins
2020-07-31 09:47:21 CEST
CC:
(none) =>
davidwhodgins An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2020-0302.html Resolution:
(none) =>
FIXED |