Critical severity9.8NVD Advisory· Published Jun 22, 2020· Updated Jun 17, 2026
CVE-2020-14983
CVE-2020-14983
Description
The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading to a buffer overflow. A malicious user can overwrite the server's stack.
Affected products
11cpe:2.3:a:chocolate-doom:chocolate_doom:3.0.0:-:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:chocolate-doom:chocolate_doom:3.0.0:-:*:*:*:*:*:*
- (no CPE)range: 3.0.0
- cpe:2.3:a:chocolate-doom:crispy_doom:5.8.0:*:*:*:*:*:*:*
- Crispy Doom/Crispy Doomdescription
- Range: 5.8.0
- osv-coords3 versionspkg:rpm/opensuse/chocolate-doom&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/chocolate-doom&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/chocolate-doom&distro=SUSE%20Package%20Hub%2015%20SP1
< 3.0.1-lp151.3.3.1+ 2 more
- (no CPE)range: < 3.0.1-lp151.3.3.1
- (no CPE)range: < 3.0.1-lp152.4.3.1
- (no CPE)range: < 3.0.1-bp151.4.3.1
Patches
Vulnerability mechanics
References
4- github.com/chocolate-doom/chocolate-doom/issues/1293nvdExploitPatchThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00002.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00007.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00012.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.