commit 7a601ddac57698e556e3ef6987e080e396f69705
Author: Michael Francis <4574480+mfrancis95@users.noreply.github.com>
AuthorDate: Thu Oct 12 21:11:30 2023 -0400
Commit: Turo Lamminen <turol@users.noreply.github.com>
CommitDate: Thu Aug 1 00:33:46 2024 +0300
Add 3.0.1 to NEWS.md
---
NEWS.md | 13 +++++++++++++
1 file changed, 13 insertions(+)
diff --git a/NEWS.md b/NEWS.md
index 8969e023..1459778e 100644
--- a/NEWS.md
+++ b/NEWS.md
@@ -93,6 +93,19 @@
* Sehacked replacements of the "empty slot" string now work.
* VOICES.WAD is now found in a case-insensitive way (thanks Mike Francis).
+## 3.0.1 (2020-06-24)
+
+This is a point release that includes two security fixes related to Chocolate
+Doom server logic.
+
+Thanks to Michał Dardas from LogicalTrust for discovering the vulnerability.
+
+### Bug fixes
+ * ([CVE-2020-14983](https://nvd.nist.gov/vuln/detail/CVE-2020-14983)) Fixed a vulnerability where
+ an unchecked `num_players` field in the server logic could allow a malicious attacker to trigger
+ arbitrary code execution against Chocolate Doom servers.
+ * Fixed an issue where a client could crash if the server sent an invalid `ticdup` setting.
+
## 3.0.0 (2017-12-30)
Chocolate Doom 3.0 is a new major revision. The main change is that