Mageia 2020-0302: chocolate-doom security update
Summary
The server in Chocolate Doom 3.0.0 doesn't validate the user-controlled
num_players value, leading to a buffer overflow. A malicious user can
overwrite the server's stack (CVE-2020-14983).
References
- https://bugs.mageia.org/show_bug.cgi?id=26915
- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14983
Resolution
MGASA-2020-0302 - Updated chocolate-doom packages fix security vulnerability
SRPMS
- 7/core/chocolate-doom-3.0.1-1.mga7