CVE-2020-11722
9.8
CRITICAL
CVSS 3.1
EPSS 3.9%
Description
Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.
How to fix CVE-2020-11722
To remediate CVE-2020-11722, upgrade the affected package to a fixed version below.
- Debian/crawl—upgrade to 2:0.25.0-1 or later
Is CVE-2020-11722 being exploited?
Low — EPSS is 3.9%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2:0.25.0-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |