sqclass.cpp in Squirrel 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possible for the attacker to break out of the squirrel script sandbox even if all dangerous functionality such as File System functions has been disabled. An . MGASA-2023-0150 - Updated squirrel/supertux packages fix security vulnerability Publication date: 24 Apr 2023 URL: https://advisories.mageia.org/MGASA-2023-0150.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-41556 sqclass.cpp in Squirrel 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possible for the attacker to break out of the squirrel script sandbox even if all dangerous functionality such as File System functions has been disabled. An attacker might abuse this bug to target (for example) Cloud services that allow customization via SquirrelScripts, or distribute malware through video games that embed a Squirrel Engine. (CVE-2021-41556) supertux has been rebuilt as it uses a bundled copy of squirrel. References: - https://bugs.mageia.org/show_bug.cgi?id=30742 - https://lists.fedoraproject.org/archives/list/
squirrel: thread_call in sqbaselib.cpp lacks a certain sq_reservestack call (CVE-2022-30292) References: - https://bugs.mageia.org/show_bug.cgi?id=30430 . MGASA-2022-0204 - Updated supertux packages fix security vulnerability Publication date: 25 May 2022 URL: https://advisories.mageia.org/MGASA-2022-0204.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-30292 squirrel: thread_call in sqbaselib.cpp lacks a certain sq_reservestack call (CVE-2022-30292) References: - https://bugs.mageia.org/show_bug.cgi?id=30430 - https://lists.fedoraproject.org/archives/list/
Fix CVE-2022-30292. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-88e3257aef 2022-05-16 02:04:05.714253 --------------------------------------------------------------------------------Name : supertux Product : Fedora 35 Version : 0.6.3 Release : 2.fc35 URL : https://www.supertux.org Summary : Jump'n run like game Description : SuperTux is a jump'n run like game, Run and jump through multiple worlds, fighting off enemies by jumping on them or bumping them from below. Grabbing power-ups and other stuff on the way. --------------------------------------------------------------------------------Update Information: Fix CVE-2022-30292 --------------------------------------------------------------------------------ChangeLog: * Thu May 5 2022 David King - 0.6.3-2 - Fix CVE-2022-30292 (#2082179) --------------------------------------------------------------------------------References: [ 1 ] Bug #2082179 - CVE-2022-30292 supertux: squirrel: thread_call in sqbaselib.cpp lacks a certain sq_reservestack call [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2082179 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-88e3257aef' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.