Bug 1212632 - VUL-0: xonotic: malicious servers could crash client or execute arbitrary code
Summary: VUL-0: xonotic: malicious servers could crash client or execute arbitrary code
Status: RESOLVED FIXED
Alias: None
Product: openSUSE Tumbleweed
Classification: openSUSE
Component: Security (show other bugs)
Version: Current
Hardware: Other Other
: P3 - Medium : Major (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: E-mail List
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-06-22 16:36 UTC by Akseli Lahtinen
Modified: 2023-06-29 22:05 UTC (History)
6 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Akseli Lahtinen 2023-06-22 16:36:49 UTC
Seems Xonotic 0.8.5 has a possible security issue: https://xonotic.org/posts/2023/xonotic-0-8-6-release/

The developers are advising to not use 0.8.5 or below to connect internet servers, so 0.8.6 is preferable.
Comment 1 Andreas Stieger 2023-06-22 16:56:53 UTC
SECURITY ALERT: a bug was discovered in versions older than 0.8.6 that is believed to be exploitable by malicious server admins to crash clients or, if they defeat mitigations, execute arbitrary code. No working exploit code is known to exist at this time, however all users are urged to upgrade immediately, and not use versions older than 0.8.6 to join online servers.

openSUSE:Backports:SLE-15-SP4:Update/xonotic 0.8.2
openSUSE:Backports:SLE-15-SP5:Update/xonotic 0.8.5
Comment 2 Andreas Stieger 2023-06-23 18:30:35 UTC
Maintenance update submitted.
Comment 3 OBSbugzilla Bot 2023-06-23 19:05:02 UTC
This is an autogenerated message for OBS integration:
This bug (1212632) was mentioned in
https://build.opensuse.org/request/show/1094942 Backports:SLE-15-SP4+Backports:SLE-15-SP5 / xonotic
Comment 4 Andreas Stieger 2023-06-29 18:16:11 UTC
Done
Comment 5 Marcus Meissner 2023-06-29 22:05:34 UTC
openSUSE-SU-2023:0162-1: An update that contains security fixes can now be installed.\n\nCategory: security (moderate)\nBug References: 1212632\nCVE References: \nJIRA References: \nSources used:\nopenSUSE Backports SLE-15-SP5 (src):    xonotic-0.8.6-bp155.2.3.1\nopenSUSE Backports SLE-15-SP4 (src):    xonotic-0.8.6-bp154.3.3.1\n\n