CVE-2020-14939

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
23/06/2020
Last modified:
01/07/2020

Description

An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts that recover a game's state. A file can be modified to put any Lua code inside, leading to arbitrary code execution while loading.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:freedroid:freedroidrpg:1.0:rc2:*:*:*:*:*:*