CVE-2015-0844: Fedoraproject Fedora

Medium severity, CVSS 5.0. EPSS: 2.3% chance of exploitation in the next 30 days.

The WML/Lua API in Battle for Wesnoth 1.7.x through 1.11.x and 1.12.x before 1.12.2 allows remote attackers to read arbitrary files via a crafted (1) campaign or (2) map file.

Affected products

  • Fedoraproject Fedora: version 20 only; version 21 only; version 22 only
  • Wesnoth Battle For Wesnoth: version 1.7.0 only; version 1.7.1 only; version 1.7.2 only; version 1.7.3 only; version 1.7.4 only; version 1.7.5 only; …

Published 2015-04-14. Last modified 2026-06-17.