foxygit / doom Log in
commit 7a601ddac57698e556e3ef6987e080e396f69705
Author:     Michael Francis <4574480+mfrancis95@users.noreply.github.com>
AuthorDate: Thu Oct 12 21:11:30 2023 -0400
Commit:     Turo Lamminen <turol@users.noreply.github.com>
CommitDate: Thu Aug 1 00:33:46 2024 +0300

    Add 3.0.1 to NEWS.md
---
 NEWS.md | 13 +++++++++++++
 1 file changed, 13 insertions(+)

diff --git a/NEWS.md b/NEWS.md
index 8969e023..1459778e 100644
--- a/NEWS.md
+++ b/NEWS.md
@@ -93,6 +93,19 @@
   * Sehacked replacements of the "empty slot" string now work.
   * VOICES.WAD is now found in a case-insensitive way (thanks Mike Francis).

+## 3.0.1 (2020-06-24)
+
+This is a point release that includes two security fixes related to Chocolate
+Doom server logic.
+
+Thanks to Michał Dardas from LogicalTrust for discovering the vulnerability.
+
+### Bug fixes
+  * ([CVE-2020-14983](https://nvd.nist.gov/vuln/detail/CVE-2020-14983)) Fixed a vulnerability where
+    an unchecked `num_players` field in the server logic could allow a malicious attacker to trigger
+    arbitrary code execution against Chocolate Doom servers.
+  * Fixed an issue where a client could crash if the server sent an invalid `ticdup` setting.
+
 ## 3.0.0 (2017-12-30)

   Chocolate Doom 3.0 is a new major revision. The main change is that