Impact
An out-of-bounds read occurs in sg_load_player_unit() when Freeciv processes savegame files that contain unit activity indices beyond the allowed range. The improper bounds check can allow a malicious actor to read beyond the intended buffer, potentially exposing a fragment of heap memory or causing the application to terminate. This flaw does not grant direct code execution but can leak sensitive data and interrupt service availability.
Affected Systems
Freeciv releases from version 3.1.0 through 3.2.5 are affected. The vulnerability is present in both the server and client components that load savegame files, so any instance of these products that accepts user-supplied or externally sourced savegames is at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity vulnerability. EPSS of less than 1% implies a very low probability of exploitation in the wild at the time of analysis. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can supply a crafted savegame file either by uploading it to a game server or providing it to a local client. Successful exploitation would result in an application crash or a partial memory disclosure, leading primarily to denial of service or limited confidentiality impact.
OpenCVE Enrichment