{"id":"MGASA-2015-0034","summary":"Updated freeciv packages fix a security vulnerability","details":"Updated freeciv packages to latest bugfix version, also fixing security vulnerability\n\nFreeciv 2.4.1 in Mageia 4 was built against an embedded version of lua 5.1,\nvulnerable to the following security issue:\n\nA heap-based overflow vulnerability was found in the way Lua handles varargs\nfunctions with many fixed parameters called with few arguments, leading to\napplication crashes or, potentially, arbitrary code execution (CVE-2014-5461,\nmga#14038).\n\nAs of this update, Freeciv is now built against the patched system version\nof lua 5.1.\n\nThis update also provides Freeciv 2.4.4, a maintenance release in the 2.4.x\nstable branch with numerous bug fixes and minor new features.\nSee the referenced release notes for details.\n","modified":"2026-04-16T04:28:45.077862Z","published":"2015-01-21T17:15:23Z","references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0034.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=15038"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=14038"},{"type":"WEB","url":"http://freeciv.wikia.com/wiki/NEWS-2.4.2"},{"type":"WEB","url":"http://freeciv.wikia.com/wiki/NEWS-2.4.3"},{"type":"WEB","url":"http://freeciv.wikia.com/wiki/NEWS-2.4.4"}],"affected":[{"package":{"name":"freeciv","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/freeciv?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.4-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0034.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}