This update provides minetest 5.6.1, the latest stable release of the open source voxel game. This updates provides a number of feature and bug fix changes compared to the previous version 5.4.0 provided in Mageia 8. See the linked release notes and changelogs for details. . MGASA-2023-0005 - Updated minetest packages fix security vulnerability Publication date: 13 Jan 2023 URL: https://advisories.mageia.org/MGASA-2023-0005.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-35978 This update provides minetest 5.6.1, the latest stable release of the open source voxel game. This updates provides a number of feature and bug fix changes compared to the previous version 5.4.0 provided in Mageia 8. See the linked release notes and changelogs for details. The update also improves compatibility with hosted game servers, which typically run and expect the latest stable release. The update also fixes a security vulnerability affecting single player with malicious mods (GHSA-663q-pcjw-27cc) In single player, a mod could set a global setting that controls the Lua script loaded to display the main menu. The script would be loaded as soon as the game session is exited. The Lua environment the menu runs in was not sandboxed and could directly interfere with the user's system. (CVE-2022-35978) References: - https://bugs.mageia.org/show_bug.cgi?id=31363 - https://blog.luanti.org/2022/08/04/5.6.0-released/ - https://docs.luanti.org/Changelog/ - https://docs.luanti.org/Changelog/ - https://docs.luanti.org/Changelog/ - https://github.com/luanti-org/luanti/security/advisories/GHSA-663q-pcjw-27cc - https://www.cve.org/CVERecord?id=CVE-2022-35978 SRPMS: - 8/core/minetest-5.6.1-1.mga8 . Mageia 2023-0005 upgrades minetest to address a major security flaw impacting single player gameplay due to harmful modifications.. Mageia Minetest Security Update, Lua Scripting Vulnerability, Single Player Game Threats. . Severity: Important. LinuxSecurity.com Team
Fix CVE-2022-30292. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-88e3257aef 2022-05-16 02:04:05.714253 --------------------------------------------------------------------------------Name : supertux Product : Fedora 35 Version : 0.6.3 Release : 2.fc35 URL : https://www.supertux.org Summary : Jump'n run like game Description : SuperTux is a jump'n run like game, Run and jump through multiple worlds, fighting off enemies by jumping on them or bumping them from below. Grabbing power-ups and other stuff on the way. --------------------------------------------------------------------------------Update Information: Fix CVE-2022-30292 --------------------------------------------------------------------------------ChangeLog: * Thu May 5 2022 David King - 0.6.3-2 - Fix CVE-2022-30292 (#2082179) --------------------------------------------------------------------------------References: [ 1 ] Bug #2082179 - CVE-2022-30292 supertux: squirrel: thread_call in sqbaselib.cpp lacks a certain sq_reservestack call [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2082179 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-88e3257aef' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Latest upstream. https://www.openwall.com/lists/oss-security/2015/06/25/2 https://www.openwall.com/lists/oss-security/2015/06/25/2. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-10964 2015-06-30 17:57:52 -------------------------------------------------------------------------------- Name : wesnoth Product : Fedora 22 Version : 1.12.4 Release : 1.fc22 URL : http://www.wesnoth.org Summary : Turn-based strategy game with a fantasy theme Description : The Battle for Wesnoth is a turn-based strategy game with a fantasy theme. Build up a great army, gradually turning raw recruits into hardened veterans. In later games, recall your toughest warriors and form a deadly host against whom none can stand. Choose units from a large pool of specialists, and hand-pick a force with the right strengths to fight well on different terrains against all manner of opposition. Fight to regain the throne of Wesnoth, of which you are the legitimate heir, or use your dread power over the Undead to dominate the land of mortals, or lead your glorious Orcish tribe to victory against the humans who dared despoil your lands. Wesnoth has many different sagas waiting to be played out. You can create your own custom units, and write your own scenarios--or even full-blown campaigns. You can also challenge your friends--or strangers--and fight multi-player epic fantasy battles. -------------------------------------------------------------------------------- Update Information: Latest upstream. https://www.openwall.com/lists/oss-security/2015/06/25/2 https://www.openwall.com/lists/oss-security/2015/06/25/2 -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 29 2015 Jon Ciesla - 1.12.4-1 - Upstream maintenance release. * Fri Jun 26 2015 Jon Ciesla - 1.12.2-3 - Patches for CVE-2015-5069 and CVE-2015-5070. * Fri Jun 19 2015 Fedora Release Engineering - 1.12.2-2 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #1236011 - CVE-2015-5070 CVE-2015-5069 wesnoth: authentication information disclosure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1236011 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update wesnoth' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
can be exploited by a local attacker to gain gid "games".. Debian Security Advisory DSA 451-1
Get the latest Linux and open source security news straight to your inbox.