The server in Chocolate Doom 3.0.0 doesn't validate the user-controlled
num_players value, leading to a buffer overflow. A malicious user can
overwrite the server's stack (CVE-2020-14983).
- https://bugs.mageia.org/show_bug.cgi?id=26915
- - https://www.cve.org/CVERecord?id=CVE-2020-14983
- 7/core/chocolate-doom-3.0.1-1.mga7
Get the latest Linux and open source security news straight to your inbox.