This bug was reported against the Debian package, but is an upstream issue :
Saved game files are composed of Lua scripts that recover a game's state. A file can be modified to put any Lua code inside, leading to arbitrary code execution while loading.
|