Bug#1031732: iortcw: CVE-2019-25104

2023-02-21 Thread Moritz Mühlenhoff
Source: iortcw X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for rtcwcoop, which seems to be a fork of iortcw, but the patches don't seem to have flown back? CVE-2019-25104[0]: | A vulnerability has been found in rtcwcoop

Bug#1031732: iortcw: CVE-2019-25104

2023-02-21 Thread Simon McVittie
On Tue, 21 Feb 2023 at 16:09:30 +0100, Moritz Mühlenhoff wrote: > CVE-2019-25104[0]: > https://github.com/rtcwcoop/rtcwcoop/pull/45 This looks like a denial of service via memory exhaustion when running a multiplayer server. For a game from 2001, I would personally say this is normal or even minor

Bug#1031732: iortcw: CVE-2019-25104

2023-02-21 Thread Moritz Muehlenhoff
On Tue, Feb 21, 2023 at 03:32:01PM +, Simon McVittie wrote: > On Tue, 21 Feb 2023 at 16:09:30 +0100, Moritz Mühlenhoff wrote: > > CVE-2019-25104[0]: > > https://github.com/rtcwcoop/rtcwcoop/pull/45 > > This looks like a denial of service via memory exhaustion when running > a multiplayer serve