Impact
A heap buffer overflow occurs in the worklist_load function of Freeciv when a savegame declares a worklist length larger than the internal 64‑element array. The overflow writes beyond the array into adjacent heap‑allocated fields, corrupting memory and potentially causing crashes, instability, or more severe exploits if the corrupted memory is used for control flow. The weakness is a classic buffer overflow (CWE‑122).
Affected Systems
All releases of Freeciv before version 3.2.6 are vulnerable. The flaw is triggered when the application processes a savegame file and is independent of operating system or hardware. Both client and server installations that accept externally supplied savegames can be affected.
Risk and Exploitability
The CVSS score of 8.5 classifies this as high severity, while the EPSS score of <1% indicates a very low exploitation probability. The vulnerability is not listed in the CISA KE savegame locally or remotely through the server’s savegame loading interface. Due to memory corruption, the effect could range from application crashes to potential privilege escalation if the corrupted memory is used for control flow. The likely attack vector is the savegame file ingestion path; this is inferred from the description and requires local access or the ability to trigger the load operation on a target system.
OpenCVE Enrichment