|
|
| |
|
| |
redeclipse: file disclosure
| Package(s): | redeclipse |
CVE #(s): | |
| Created: | August 20, 2012 |
Updated: | August 22, 2012 |
| Description: |
From the Fedora advisory:
A flaw was found in the way Red Eclipse handled config files. In cube2-engine games, game maps can be transmitted either from the server to a client, or from client to client. These maps include a config file (mapname.cfg) in "cubescript" format, which allows for an attacker to send a malicious script via a new map. This map must either be chosen by an administrator on the server, or created in co-operative editing mode. A malicious script could then be used to read or write to any files that the user running the client has access to when the victim loads a map with the malicious configuration file. |
| Alerts: |
|
( Log in to post comments)
|
|
|