CVE-2010-2445: OS Command Injection
freeciv 2.2 before 2.2.1 and 2.3 before 2.3.0 allows attackers to read arbitrary files or execute arbitrary commands via a scenario that contains Lua functionality, related to the (1) os, (2) io, (3) package, (4) dofile, (5) loadfile, (6) loadlib, (7) module, and (8) require modules or functions.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2445?
CVE-2010-2445 has a medium severity rating due to its potential to allow attackers to read arbitrary files and execute commands.
How do I fix CVE-2010-2445?
To fix CVE-2010-2445, upgrade Freeciv to version 2.2.1 or 2.3.0 or later.
What versions of Freeciv are affected by CVE-2010-2445?
Freeciv versions 2.2.0 and 2.3.0 dev versions before their respective updates are affected by CVE-2010-2445.
Can CVE-2010-2445 allow remote code execution?
Yes, CVE-2010-2445 can potentially enable remote code execution due to the exploitable Lua functionality.
What types of attacks can be performed using CVE-2010-2445?
Attackers can leverage CVE-2010-2445 to read arbitrary files or execute arbitrary commands through crafted scenarios.