Vulnerability Details CVE-2015-5070
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is used, allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-5069.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 70.2%
CVSS Severity
CVSS v3 Score 3.1
CVSS v2 Score 3.5
Products affected by CVE-2015-5070
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.10.0
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.0
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.1
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.10
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.11
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.12
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.13
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.14
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.15
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.16
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.17
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.18
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.19
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.2
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.3
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.4
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.5
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.6
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.7
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.8
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.11.9
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.12.0
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.12.1
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.12.2
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.13.0
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.0
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.1
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.10-1.8
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.11-1.8
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.12-1.8
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.13-1.8
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.14-1.8
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.15-1.8
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.2
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.3
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.4
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.5
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.6
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.7
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.8
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.7.9
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.8.0
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.0
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.1
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.10
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.11
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.12
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.13
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.14
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.2
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.3
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.4
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.5
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.6
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.7
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.8
-
cpe:2.3:a:wesnoth:battle_for_wesnoth:1.9.9
-
cpe:2.3:o:fedoraproject:fedora:21
-
cpe:2.3:o:fedoraproject:fedora:22