Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Code execution via malicious map file (CVE-2021-43518) References: - https://bugs.mageia.org/show_bug.cgi?id=30717 - https://lists.fedoraproject.org/archives/list/
Fix for CVE-2021-43518.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-f281321e55 2022-08-06 01:52:03.199283 --------------------------------------------------------------------------------Name : teeworlds Product : Fedora 36 Version : 0.7.5 Release : 10.fc36 URL : https://www.teeworlds.com/ Summary : Online multi-player platform 2D shooter Description : The game features cartoon-themed graphics and physics, and relies heavily on classic shooter weaponry and gameplay. The controls are heavily inspired by the FPS genre of computer games. --------------------------------------------------------------------------------Update Information: Fix for CVE-2021-43518. --------------------------------------------------------------------------------ChangeLog: * Thu Jul 28 2022 Gwyn Ciesla - 0.7.5-10 - Patch for CVE-2021-43518 * Sat Jul 23 2022 Fedora Release Engineering - 0.7.5-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2035359 - CVE-2021-43518 teeworlds: code execution via malicious map file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2035359 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-f281321e55' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list
Teeworlds could be made to crash if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-4553-1 September 28, 2020 teeworlds vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Teeworlds could be made to crash if it received specially crafted network traffic. Software Description: - teeworlds: online multi-player platform 2D shooter Details: It was discovered that Teeworlds server did not properly handler certain network traffic. A remote, unauthenticated attacker could use this vulnerability to cause Teeworlds server to crash. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: teeworlds-server 0.7.2-5ubuntu1.1 In general, a standard system update will make all the necessary changes. References: CVE-2020-12066 Package Information: https://launchpad.net/ubuntu/+source/teeworlds/0.7.2-5ubuntu1.1 -- ubuntu-security-announce mailing list
It was discovered that insufficient sanitising of received network packets in the game server of Teeworlds, an online multi-player platform 2D shooter, could result in denial of service. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4763-1
0.7.5. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-0d6b80678a 2020-05-08 03:31:40.231699 --------------------------------------------------------------------------------Name : teeworlds Product : Fedora 30 Version : 0.7.5 Release : 1.fc30 URL : https://www.teeworlds.com/ Summary : Online multi-player platform 2D shooter Description : The game features cartoon-themed graphics and physics, and relies heavily on classic shooter weaponry and gameplay. The controls are heavily inspired by the FPS genre of computer games. --------------------------------------------------------------------------------Update Information: 0.7.5 --------------------------------------------------------------------------------ChangeLog: * Mon Apr 20 2020 Gwyn Ciesla - 0.7.5-1 - 0.7.5 * Fri Jan 31 2020 Fedora Release Engineering - 0.7.4-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Mon Dec 30 2019 Gwyn Ciesla - 0.7.4-2 - bump EVR for koji error * Mon Dec 30 2019 Gwyn Ciesla - 0.7.4-1 - 0.7.4 * Fri Aug 9 2019 Gwyn Ciesla - 0.7.3.1-5 - Path fix. * Fri Aug 9 2019 Gwyn Ciesla - 0.7.3.1-4 - Put a copy of icon in a place flatpak will use. * Sat Jul 27 2019 Fedora Release Engineering - 0.7.3.1-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1829193 - CVE-2019-20787 teeworlds: there's an integer overflow when computing a tilemap size [fedora-30] https://bugzilla.redhat.com/show_bug.cgi?id=1829193 [ 2 ] Bug #1829537 - CVE-2020-12066 teeworlds: allows an attacker force the server to repetitively shut down [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1829537 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c'dnf upgrade --advisory FEDORA-2020-0d6b80678a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Updated teeworlds packages fix security vulnerabilities Teeworlds before 0.7.4 is subject to an integer overflow when computing a tilemap size (CVE-2019-20787). . MGASA-2020-0191 - Updated teeworlds packages fix security vulnerabilities Publication date: 05 May 2020 URL: https://advisories.mageia.org/MGASA-2020-0191.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-20787, CVE-2020-12066 Updated teeworlds packages fix security vulnerabilities Teeworlds before 0.7.4 is subject to an integer overflow when computing a tilemap size (CVE-2019-20787). Teeworlds before 0.7.5 is subject to a denial of service against the server (CVE-2020-12066). This update fixes both vulnerabilities by updating from Teeworlds 0.7.3.1 to 0.7.5, including additional features and bug fixes (see the referenced changelogs for details). References: - https://bugs.mageia.org/show_bug.cgi?id=26553 - - https://www.teeworlds.com/?page=journal&id=13357 - https://www.teeworlds.com/forum/viewtopic.php?id=14784 - https://www.cve.org/CVERecord?id=CVE-2019-20787 - https://www.cve.org/CVERecord?id=CVE-2020-12066 SRPMS: - 7/core/teeworlds-0.7.5-1.mga7 . Revised teeworlds distributions tackle integer overflows and DoS vulnerabilities, enhancing safety for Mageia clients.. teeworlds updates, Mageia vulnerabilities, integer overflow, denial of service. . LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for teeworlds ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0563-1 Rating: moderate References: #1170252 #1170253 Cross-References: CVE-2019-20787 CVE-2020-12066 Affected Products: openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for teeworlds to version 0.7.5 fixes the following issues: Security issues fixed: - CVE-2020-12066: Fixed a denial of service against the server (boo#1170252) - CVE-2019-20787: Fixed an integer overflow when computing a tilemap size (boo#1170253) Non-security issues fixed: - multiple smaller bug fixes and improvements. This update was imported from the openSUSE:Leap:15.1:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2020-563=1 Package List: - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64): teeworlds-0.7.5-bp151.2.6.1 References: https://www.suse.com/security/cve/CVE-2019-20787.html https://www.suse.com/security/cve/CVE-2020-12066.html https://bugzilla.suse.com/1170252 https://bugzilla.suse.com/1170253 -- . This patch mitigates various security flaws in teeworlds for openSUSE, featuring essential repairs to avert server interruptions.. openSUSE Update, teeworlds Security Fix, Denial Of Service, Integer Overflow. . LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for teeworlds ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0557-1 Rating: moderate References: #1170252 #1170253 Cross-References: CVE-2019-20787 CVE-2020-12066 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for teeworlds to version 0.7.5 fixes the following issues: Security issues fixed: - CVE-2020-12066: Fixed a denial of service against the server (boo#1170252) - CVE-2019-20787: Fixed an integer overflow when computing a tilemap size (boo#1170253) Non-security issues fixed: - multiple smaller bug fixes and improvements. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-557=1 Package List: - openSUSE Leap 15.1 (x86_64): teeworlds-0.7.5-lp151.2.6.1 teeworlds-debuginfo-0.7.5-lp151.2.6.1 teeworlds-debugsource-0.7.5-lp151.2.6.1 References: https://www.suse.com/security/cve/CVE-2019-20787.html https://www.suse.com/security/cve/CVE-2020-12066.html https://bugzilla.suse.com/1170252 https://bugzilla.suse.com/1170253 -- . An openSUSE Security Update addresses two vulnerabilities identified in teeworlds: a Denial of Service (DoS) concern and a potential integer overflow flaw.. openSUSE Security, teeworlds Update, Moderate Security Fix, Software Patch. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.