CVE-2011-1932: Path Traversal
Published Dec 5, 2011
·Updated
Directory traversal vulnerability in io/filesystem/filesystem.cc in Widelands before 15.1 might allow remote attackers to overwrite arbitrary files via . (dot) characters in a pathname that is used for a file transfer in an Internet game.
Affected Software
20 affected components
Widelands Widelands=build1
Widelands Widelands=build10
Widelands Widelands=build10_release_candidate
Widelands Widelands=build11
Widelands Widelands=build11_release_candidate
Widelands Widelands=build12
Widelands Widelands=build12_release_candidate
Widelands Widelands=build13
Widelands Widelands=build13_release_candidate
Widelands Widelands=build13_release_candidate2
Widelands Widelands=build14
Widelands Widelands=build14_release_candidate
Widelands Widelands=build2
Widelands Widelands=build3
Widelands Widelands=build4
Widelands Widelands=build5
Widelands Widelands=build6
Widelands Widelands=build7
Widelands Widelands=build8
Widelands Widelands=build9
Remediation
Event History
Dec 5, 2011
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-1932?
CVE-2011-1932 is classified as a high severity vulnerability that could potentially allow file overwrites.
2
How do I fix CVE-2011-1932?
To fix CVE-2011-1932, upgrade to Widelands version 15.1 or later, which addresses the directory traversal issue.
3
What versions of Widelands are affected by CVE-2011-1932?
CVE-2011-1932 affects Widelands versions from build1 to build14.
4
Can CVE-2011-1932 lead to remote attacks?
Yes, CVE-2011-1932 can allow remote attackers to exploit the vulnerability by using crafted pathnames.
5
What type of vulnerability is CVE-2011-1932?
CVE-2011-1932 is a directory traversal vulnerability that enables unauthorized file access.