Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.
CPE | Name | Operator | Version |
---|---|---|---|
dungeon_crawl_stone_soup | lt | 0.25 |
lists.opensuse.org/opensuse-security-announce/2020-04/msg00037.html
dpmendenhall.blogspot.com/2020/03/dungeon-crawl-stone-soup.html
github.com/crawl/crawl/commit/768f60da87a3fa0b5561da5ade9309577c176d04
github.com/crawl/crawl/commit/fc522ff6eb1bbb85e3de60c60a45762571e48c28
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6QLPN635S7J3MUXLIHYK6MDAHEIASFYP/
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XNXK7QE7EA7XSDDNOWX2A6MJNWOIYCTC/