The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is used, allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-5069.
2017-09-26T14:29:00.330
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 3.1 (LOW)
AV:N/AC:M/Au:S/C:P/I:N/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | wesnoth | battle_for_wesnoth | ≤ 1.12.2 | Yes |
Application | wesnoth | battle_for_wesnoth | 1.13.0 | Yes |
Operating System | fedoraproject | fedora | 21 | Yes |
Operating System | fedoraproject | fedora | 22 | Yes |