CVE-2022-25010: Critical severity stepmania vulnerability
Published Mar 1, 2022
·Updated
The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.
Affected Software
6 affected components
StepMania StepMania<=5.0.12
StepMania StepMania=5.1.0-alpha
StepMania StepMania=5.1.0-alpha2
StepMania StepMania=5.1.0-alpha3
StepMania StepMania=5.1.0-beta1
StepMania StepMania=5.1.0-beta2
Remediation
Patch Available
Event History
Mar 1, 2022
CVE Published
via MITRE·10:24 PM
Data Sourced
via MITRE·10:24 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-25010?
CVE-2022-25010 is considered a critical severity vulnerability due to its potential to allow unauthorized access to the entire file system.
2
How do I fix CVE-2022-25010?
To mitigate CVE-2022-25010, upgrade Stepmania to version 5.1b3 or later, where the vulnerability is addressed.
3
What versions of Stepmania are affected by CVE-2022-25010?
CVE-2022-25010 affects Stepmania versions 5.0.12 and earlier, as well as 5.1.0 in its alpha and beta releases.
4
What kind of access does CVE-2022-25010 provide to attackers?
CVE-2022-25010 allows attackers to gain unrestricted access to the entire file system of vulnerable Stepmania installations.
5
Is there any workaround for CVE-2022-25010?
There are no known effective workarounds for CVE-2022-25010 other than upgrading to a fixed version.