VYPR
Unrated severityNVD Advisory· Published Jul 8, 2010· Updated Apr 29, 2026

CVE-2010-2445

CVE-2010-2445

Description

freeciv 2.2 before 2.2.1 and 2.3 before 2.3.0 allows attackers to read arbitrary files or execute arbitrary commands via a scenario that contains Lua functionality, related to the (1) os, (2) io, (3) package, (4) dofile, (5) loadfile, (6) loadlib, (7) module, and (8) require modules or functions.

Affected products

6
  • Freeciv/Freeciv6 versions
    cpe:2.3:a:freeciv:freeciv:2.2.0:beta2:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:freeciv:freeciv:2.2.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:freeciv:freeciv:2.2.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:freeciv:freeciv:2.2.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:freeciv:freeciv:2.3.0:dev:*:*:*:*:*:*
    • cpe:2.3:a:freeciv:freeciv:2.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:freeciv:freeciv:2.2.0:beta1:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.