FreeBSD : wesnoth -- disclosure of .pbl files with lowercase, uppercase, and mixed-case extension (2a8b7d21-1ecc-11e5-a4a5-002590263bf5)

medium Nessus Plugin ID 84483

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

Ignacio R. Morelle reports :

As mentioned in the Wesnoth 1.12.4 and Wesnoth 1.13.1 release announcements, a security vulnerability targeting add-on authors was found (bug #23504) which allowed a malicious user to obtain add-on server passphrases from the client's .pbl files and transmit them over the network, or store them in saved game files intended to be shared by the victim. This vulnerability affects all existing releases up to and including versions 1.12.2 and 1.13.0. Additionally, version 1.12.3 included only a partial fix that failed to guard users against attempts to read from .pbl files with an uppercase or mixed-case extension. CVE-2015-5069 and CVE-2015-5070 have been assigned to the vulnerability affecting .pbl files with a lowercase extension, and .pbl files with an uppercase or mixed-case extension, respectively.

Solution

Update the affected package.

See Also

http://forums.wesnoth.org/viewtopic.php?t=42776

http://forums.wesnoth.org/viewtopic.php?t=42775

http://www.nessus.org/u?28cb1aa1

Plugin Details

Severity: Medium

ID: 84483

File Name: freebsd_pkg_2a8b7d211ecc11e5a4a5002590263bf5.nasl

Version: 2.7

Type: local

Published: 7/1/2015

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 1.4

CVSS v2

Risk Factor: Medium

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS v3

Risk Factor: Medium

Base Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:wesnoth, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 7/1/2015

Vulnerability Publication Date: 6/28/2015

Reference Information

CVE: CVE-2015-5069, CVE-2015-5070