Bug 1211670 (CVE-2023-31518) - VUL-0: CVE-2023-31518: teeworlds: heap use-after-free in the component CDataFileReader::GetItem
Summary: VUL-0: CVE-2023-31518: teeworlds: heap use-after-free in the component CDataF...
Status: NEW
Alias: CVE-2023-31518
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Martin Hauke
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/367287/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-05-24 06:16 UTC by Alexander Bergmann
Modified: 2024-05-07 11:54 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2023-05-24 06:16:47 UTC
CVE-2023-31518

A heap use-after-free in the component CDataFileReader::GetItem of teeworlds
v0.7.5 allows attackers to cause a Denial of Service (DoS) via a crafted map
file.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-31518
https://www.cve.org/CVERecord?id=CVE-2023-31518
https://mmmds.pl/fuzzing-map-parser-part-1-teeworlds/
https://gist.github.com/manba-bryant/9ca95d69c65f4d2c55946932c946fb9b
https://github.com/teeworlds/teeworlds/issues/2970
Comment 1 Robert Frohl 2024-05-07 11:54:20 UTC
@Martin: would you be interested to submit the fix, even if you are not the maintainer ?