The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML.
2017-09-26T14:29:00.250
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 4.3 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | wesnoth | battle_for_wesnoth | ≤ 1.12.2 | Yes |
Application | wesnoth | battle_for_wesnoth | 1.13.0 | Yes |
Operating System | fedoraproject | fedora | 21 | Yes |
Operating System | fedoraproject | fedora | 22 | Yes |