The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-09-26T14:00:00

Updated: 2024-08-06T06:32:32.740Z

Reserved: 2015-06-25T00:00:00

Link: CVE-2015-5069

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-09-26T14:29:00.250

Modified: 2017-10-10T14:54:49.397

Link: CVE-2015-5069

cve-icon Redhat

No data.