[Secure-testing-team] Bug#770514: teeworlds: security vulnerability (Memory reads, Segmentation Fault)

Markus Koschany apo at gambaru.de
Fri Nov 21 21:42:15 UTC 2014


Package: src:teeworlds
Version: 0.6.1+dfsg-1
Severity: grave
Tags: security


Hi,

yesterday the developers of Teeworld announced a security
vulnerability in Teeworld's server for the complete 0.6.x series. That
means stable is also affected.

https://www.teeworlds.com/?page=news&id=11200


I am raising the severity to grave since the post states that the
vulnerability includes "Memory reads, Segmentation Fault".

They released a bugfix release, 0.6.3 with the following bugfixes

 * Fix the above-mentioned security vulnerability (Memory reads,
   Segmentation Fault) in all 0.6.x servers.

 * Fix server crash in the console code.

 * Fix master server lookup for servers.

 * Fix scripts/make_release.py script.

 * Fix client crash when opening a map with an invalid version.

Regards,

Markus



More information about the Secure-testing-team mailing list