Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

openSUSE Backports: 2023:0162-1 Moderate: Xonotic Exploit Threat

opensuse
Calendar Grey June 29, 2023
Dist Opensuse Esm H88
A security patch for xonotic resolves a vulnerability that could enable code execution by rogue server operators.
An update that contains security fixes can now be installed

Description

This update for xonotic fixes the following issues:

Update to version 0.8.6

SECURITY ALERT: A bug was discovered in versions older than 0.8.6 that is

believed to be exploitable by malicious server admins to crash clients or,

if they defeat mitigations, execute arbitrary code. (boo#1212632)

update to 0.8.5:

* https://xonotic.org/posts/2022/xonotic-0-8-5-release/

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP5:

zypper in -t patch openSUSE-2023-162=1

- openSUSE Backports SLE-15-SP4:

zypper in -t patch openSUSE-2023-162=1

Package List

- openSUSE Backports SLE-15-SP5 (aarch64 ppc64le s390x x86_64):

xonotic-0.8.6-bp155.2.3.1

xonotic-debuginfo-0.8.6-bp155.2.3.1

xonotic-debugsource-0.8.6-bp155.2.3.1

xonotic-server-0.8.6-bp155.2.3.1

xonotic-server-debuginfo-0.8.6-bp155.2.3.1

- openSUSE Backports SLE-15-SP5 (noarch):

xonotic-data-0.8.6-bp155.2.3.1

- openSUSE Backports SLE-15-SP4 (aarch64 ppc64le s390x x86_64):

xonotic-0.8.6-bp154.3.3.1

xonotic-server-0.8.6-bp154.3.3.1

- openSUSE Backports SLE-15-SP4 (noarch):

xonotic-data-0.8.6-bp154.3.3.1

References

https://bugzilla.suse.com/1212632

Announcement ID: openSUSE-SU-2023:0162-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP4 openSUSE Backports SLE-15-SP5 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here