Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://twitter.com/relogicgames | third party advisory |
https://vuln.ryotak.me/advisories/42 | third party advisory |
https://store.steampowered.com/news/app/105600/view/3062989030626131236 | third party advisory release notes |
https://terraria.fandom.com/wiki/1.4.2.3 | third party advisory release notes |