Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2022-35978: minetest: Mod scripts can escape sandbox in single player | ||
---|---|---|---|
Product: | [openSUSE] openSUSE Distribution | Reporter: | Hu <cathy.hu> |
Component: | Security | Assignee: | Dmitriy Perlow <dap.darkness> |
Status: | NEW --- | QA Contact: | Security Team bot <security-team> |
Severity: | Minor | ||
Priority: | P3 - Medium | CC: | christophe, jsegitz, opensuse, rpm, simon.vogl |
Version: | Leap 15.4 | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/339900/ | ||
Whiteboard: | |||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Hu
2022-08-16 08:46:40 UTC
Affected: - openSUSE:Backports:SLE-15-SP3/minetest 5.2.0 - openSUSE:Backports:SLE-15-SP4/minetest 5.4.1 - openSUSE:Factory/minetest 5.5.1 Unfortunately I'm currently on vacation and can't fix the issue right now - once I'm back in about 8 days I'll try to update Minetest to 5.6.0 in TW ASAP. I have zero experience when it comes to packaging for Leap so the patch backport might take a lot longer / I might not be able to do that at all. For now I'd advise all users to switch to the Flatpak version of minetest until the issue is resolved. This is an autogenerated message for OBS integration: This bug (1202423) was mentioned in https://build.opensuse.org/request/show/998676 Backports:SLE-15-SP3+Backports:SLE-15-SP4 / minetest openSUSE-SU-2023:0001-1: An update that solves one vulnerability and has two fixes is now available. Category: security (important) Bug References: 1181400,1193141,1202423 CVE References: CVE-2022-35978 JIRA References: Sources used: openSUSE Backports SLE-15-SP4 (src): minetest-5.6.0-bp154.2.3.5 openSUSE Backports SLE-15-SP3 (src): minetest-5.6.0-bp153.2.3.1 |