The WML/Lua API in Battle for Wesnoth 1.7.x through 1.11.x and 1.12.x before 1.12.2 allows remote attackers to read arbitrary files via a crafted (1) campaign or (2) map file.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156001.html | vendor advisory |
http://www.debian.org/security/2015/dsa-3218 | vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155031.html | vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155968.html | vendor advisory |
http://forums.wesnoth.org/viewtopic.php?t=41872 | vendor advisory |
http://forums.wesnoth.org/viewtopic.php?t=41870 | vendor advisory |