Wiz Agents & Workflows are here

CVE-2022-6083
Linux openSUSE vulnerability analysis and mitigation

Overview

A buffer overflow vulnerability exists in the Modpack Installer utility's handling of modpack URLs in Freeciv versions < 2.6.7 and freeciv-3.0 < 3.0.3. The vulnerability was discovered and disclosed on August 5, 2022, affecting the URL handling functionality in the Modpack Installer component (Freeciv Disclosure).

Technical details

The vulnerability occurs when specially crafted URLs without any '/' characters are processed, resulting in an underflowing length calculation of (unsigned)(-1). This causes the entire NULL-terminated string given as 'URL' to be written beyond the allocated buffer, leading to a buffer overflow condition (Freeciv Disclosure).

Impact

The buffer overflow vulnerability could potentially allow attackers to write data beyond allocated memory boundaries, which might lead to arbitrary code execution or program crashes when processing specially crafted modpack URLs (Freeciv Disclosure).

Mitigation and workarounds

Users are advised to upgrade to Freeciv version 2.6.7 or freeciv-3.0.3 or later. For those unable to perform a full version update, a patch for this specific issue is available in the bug tracker ticket #45299. The fixed versions can be downloaded from the official Freeciv website (Freeciv Disclosure).

Additional resources


SourceThis report was generated using AI

Related Linux openSUSE vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-3945HIGH8.7
  • Linux DebianLinux Debian
  • tinyproxy
NoYesMar 30, 2026
CVE-2026-2272MEDIUM4.3
  • Linux DebianLinux Debian
  • gimp-devel
NoYesMar 26, 2026
CVE-2026-2271LOW3.3
  • Linux DebianLinux Debian
  • gimp:2.8::gimp-devel
NoYesMar 26, 2026
CVE-2026-0968LOW3.1
  • Linux DebianLinux Debian
  • libssh-devel
NoYesMar 26, 2026
CVE-2026-2239LOW2.8
  • Linux DebianLinux Debian
  • gimp:2.8::pygobject2
NoYesMar 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management