Debian DSA-1386-1 : wesnoth - programming error

high Nessus Plugin ID 27043

Synopsis

The remote Debian host is missing a security-related update.

Description

A problem has been discovered in the processing of chat messages.
Overly long messages are truncated by the server to a fixed length, without paying attention to the multibyte characters. This leads to invalid UTF-8 on clients and causes an uncaught exception. Note that both wesnoth and the wesnoth server are affected.

Solution

Upgrade the wesnoth packages.

For the old stable distribution (sarge) this problem has been fixed in version 0.9.0-6 and in version 1.2.7-1~bpo31+1 of sarge-backports.

For the stable distribution (etch) this problem has been fixed in version 1.2-2 and in version 1.2.7-1~bpo40+1 of etch-backports.

Packages for the oldstable mips architecture will be added to the archive later.

See Also

https://www.debian.org/security/2007/dsa-1386

Plugin Details

Severity: High

ID: 27043

File Name: debian_DSA-1386.nasl

Version: 1.16

Type: local

Agent: unix

Published: 10/15/2007

Updated: 1/4/2021

Supported Sensors: Agentless Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:wesnoth, cpe:/o:debian:debian_linux:3.1, cpe:/o:debian:debian_linux:4.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Patch Publication Date: 10/15/2007

Reference Information

CVE: CVE-2007-3917

CWE: 134

DSA: 1386