Bug 1212632

Summary: VUL-0: xonotic: malicious servers could crash client or execute arbitrary code
Product: [openSUSE] openSUSE Tumbleweed Reporter: Akseli Lahtinen <akselmo>
Component: SecurityAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: E-mail List <qa-bugs>
Severity: Major    
Priority: P3 - Medium CC: Andreas.Stieger, dap.darkness, meissner, opensuse, rpm, werner
Version: Current   
Target Milestone: ---   
Hardware: Other   
OS: Other   
Whiteboard:
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Akseli Lahtinen 2023-06-22 16:36:49 UTC
Seems Xonotic 0.8.5 has a possible security issue: https://xonotic.org/posts/2023/xonotic-0-8-6-release/

The developers are advising to not use 0.8.5 or below to connect internet servers, so 0.8.6 is preferable.
Comment 1 Andreas Stieger 2023-06-22 16:56:53 UTC
SECURITY ALERT: a bug was discovered in versions older than 0.8.6 that is believed to be exploitable by malicious server admins to crash clients or, if they defeat mitigations, execute arbitrary code. No working exploit code is known to exist at this time, however all users are urged to upgrade immediately, and not use versions older than 0.8.6 to join online servers.

openSUSE:Backports:SLE-15-SP4:Update/xonotic 0.8.2
openSUSE:Backports:SLE-15-SP5:Update/xonotic 0.8.5
Comment 2 Andreas Stieger 2023-06-23 18:30:35 UTC
Maintenance update submitted.
Comment 3 OBSbugzilla Bot 2023-06-23 19:05:02 UTC
This is an autogenerated message for OBS integration:
This bug (1212632) was mentioned in
https://build.opensuse.org/request/show/1094942 Backports:SLE-15-SP4+Backports:SLE-15-SP5 / xonotic
Comment 4 Andreas Stieger 2023-06-29 18:16:11 UTC
Done
Comment 5 Marcus Meissner 2023-06-29 22:05:34 UTC
openSUSE-SU-2023:0162-1: An update that contains security fixes can now be installed.\n\nCategory: security (moderate)\nBug References: 1212632\nCVE References: \nJIRA References: \nSources used:\nopenSUSE Backports SLE-15-SP5 (src):    xonotic-0.8.6-bp155.2.3.1\nopenSUSE Backports SLE-15-SP4 (src):    xonotic-0.8.6-bp154.3.3.1\n\n