First published: Tue Mar 01 2022(Updated: )
The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Stepmania | <=5.0.12 | |
Stepmania | =5.1.0-alpha | |
Stepmania | =5.1.0-alpha2 | |
Stepmania | =5.1.0-alpha3 | |
Stepmania | =5.1.0-beta1 | |
Stepmania | =5.1.0-beta2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25010 is considered a critical severity vulnerability due to its potential to allow unauthorized access to the entire file system.
To mitigate CVE-2022-25010, upgrade Stepmania to version 5.1b3 or later, where the vulnerability is addressed.
CVE-2022-25010 affects Stepmania versions 5.0.12 and earlier, as well as 5.1.0 in its alpha and beta releases.
CVE-2022-25010 allows attackers to gain unrestricted access to the entire file system of vulnerable Stepmania installations.
There are no known effective workarounds for CVE-2022-25010 other than upgrading to a fixed version.