CVE-2015-5070: Infoleak
The (1) filesystem::getwmllocation function in filesystem.cpp and (2) islegalfile function in filesystemboost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is used, allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-5069.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5070?
CVE-2015-5070 is classified as a medium severity vulnerability.
How do I fix CVE-2015-5070?
To fix CVE-2015-5070, update Battle for Wesnoth to version 1.12.4 or 1.13.1 or later.
What are the potential impacts of CVE-2015-5070?
CVE-2015-5070 may allow remote attackers to obtain sensitive information from the filesystem.
Which versions of Battle for Wesnoth are affected by CVE-2015-5070?
Battle for Wesnoth versions before 1.12.4 and 1.13.0 are affected by CVE-2015-5070.
Does CVE-2015-5070 affect Fedora operating systems?
Yes, CVE-2015-5070 affects Fedora 21 and 22 when running vulnerable versions of Battle for Wesnoth.