VDB
CVE-2021-43518
CVE-2021-43518
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Teeworlds up to and including 0.7.5 is vulnerable to Buffer Overflow. A map parser does not validate m_Channels value coming from a map file, leading to a buffer overflow. A malicious server may offer a specially crafted map that will overwrite client's stack causing denial of service or code execution.
EPSS 0.59% · 69.7th percentile
Risk Scores
CVSS 2.0
6.800000190734863
EPSS Score
0.59%
69.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| fedoraproject | fedora | 35, 36 |
| teeworlds | teeworlds | 0 |
| n/a | n/a | n/a |
Timeline
- Dec 15, 2021 CVE Published
- Dec 16, 2021 EPSS Score
- Feb 8, 2022 EPSS Score
- Apr 4, 2022 EPSS Score
- May 28, 2022 EPSS Score
- Jul 22, 2022 EPSS Score
- Sep 15, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
- Jan 1, 2023 EPSS Score
- Feb 24, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 20, 2023 EPSS Score
References
- https://github.com/teeworlds/teeworlds/issues/2981 url
- https://mmmds.pl/fuzzing-map-parser-part-1-teeworlds/ url
- FEDORA-2022-f446c92b48 vendor-advisory
- FEDORA-2022-f281321e55 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-43518 advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JIYZ7EVY6NZBM7FQF6GVUARYO6MKSEAT url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OS2LI2RHQNUKUT3FKWYHRC27PLRWCHMZ url
- https://mmmds.pl/fuzzing-map-parser-part-1-teeworlds url