Bug 1170252 - (CVE-2020-12066) VUL-0: CVE-2020-12066: teeworld: denial of service against server
(CVE-2020-12066)
VUL-0: CVE-2020-12066: teeworld: denial of service against server
Status: NEW
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Martin Hauke
Security Team bot
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-04-22 17:56 UTC by Marcus Meissner
Modified: 2020-04-29 10:15 UTC (History)
0 users

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2020-04-22 17:56:58 UTC
https://www.teeworlds.com/forum/viewtopic.php?id=14785
https://github.com/teeworlds/teeworlds/commit/c68402fa7e279d42886d5951d1ea8ac2facc1ea5

An exploit was discovered, that allows to crash any 0.7 Teeworlds server. Though it does not compromise the security of the host (e.g. no arbitrary accesses in memory) it lets an attacker force a server to repetitively shut down.

The 0.7.5 release is a security update that aims to patch this server exploit. As such, it is very light in features, and is mostly made of fixes. You can find the full changelog here. If you are not a server host, it is not necessary to update. If you are hosting a server modification, you should at least consider to apply c68402fa7e2.
Comment 1 Martin Hauke 2020-04-23 19:31:55 UTC
Should be fixed with an update to version 0.7.5:
Factory SR#796693
Leap15.1 SR#796694
Comment 2 Swamp Workflow Management 2020-04-23 20:00:05 UTC
This is an autogenerated message for OBS integration:
This bug (1170252) was mentioned in
https://build.opensuse.org/request/show/796694 15.1 / teeworlds
Comment 3 Swamp Workflow Management 2020-04-27 22:17:29 UTC
openSUSE-SU-2020:0557-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1170252,1170253
CVE References: CVE-2019-20787,CVE-2020-12066
Sources used:
openSUSE Leap 15.1 (src):    teeworlds-0.7.5-lp151.2.6.1
Comment 4 Swamp Workflow Management 2020-04-29 10:15:10 UTC
openSUSE-SU-2020:0563-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1170252,1170253
CVE References: CVE-2019-20787,CVE-2020-12066
Sources used:
openSUSE Backports SLE-15-SP1 (src):    teeworlds-0.7.5-bp151.2.6.1