Описание
Security update for minetest
This update for minetest fixes the following issues:
Update to version 5.6.0
- Fix CVE-2022-35978 ( boo#1202423 ): Mod scripts can escape sandbox in single player mode
namein game.conf is deprecated for the game title, usetitleinstead- Add depth sorting for node faces
- Various bug fixes
- Full changes: https://dev.minetest.net/Changelog#5.5.0_.E2.86.92_5.6.0
- Introduced mbranch-protection=none CXX flag to resolve boo#1193141 (aarch64).
Update to version 5.5.0 & 5.5.1:
- Full log for version 5.5.0: https://dev.minetest.net/Changelog#5.4.0_.E2.86.92_5.5.0
- This release switches from Irrlicht to our own fork called IrrlichtMt.
- Full log for version 5.5.1: https://dev.minetest.net/Changelog#5.5.0_.E2.86.92_5.5.1
- This is a maintenance release based on 5.5.0, it contains bugfixes but no new features.
-
Added hardening to systemd service(s) (boo#1181400).
-
Update to version 5.4.1:
- This is a maintenance release based on 5.4.0, it contains bugfixes but no new features.
-
Update to version 5.4.0
- Full log: https://dev.minetest.net/Changelog#5.3.0_.E2.86.92_5.4.0
- Removed support for bumpmapping, generated normal maps and parallax occlusion
- By default, the crosshair will now change to an 'X' when pointing to objects
- Prevent players accessing inventories of other players
- Prevent interacting with items out of the hotbar
- Prevent players from being able to modify ItemStack meta
-
Update to version 5.3.0. (see https://dev.minetest.net/Changelog#5.2.0_.E2.86.92_5.3.0)
- Formspec improvements, including a scrolling GUI element
- Performance improvements to the Server and API
- Many bug fixes and small features
-
Now requires desktop-file-utils version >= 0.25.
Список пакетов
SUSE Package Hub 15 SP3
SUSE Package Hub 15 SP4
openSUSE Leap 15.3
openSUSE Leap 15.4
Ссылки
- E-Mail link for openSUSE-SU-2023:0001-1
- SUSE Security Ratings
- SUSE Bug 1181400
- SUSE Bug 1193141
- SUSE Bug 1202423
- SUSE CVE CVE-2022-35978 page
Описание
Minetest is a free open-source voxel game engine with easy modding and game creation. In **single player**, a mod can set a global setting that controls the Lua script loaded to display the main menu. The script is then loaded as soon as the game session is exited. The Lua environment the menu runs in is not sandboxed and can directly interfere with the user's system. There are currently no known workarounds.
Затронутые продукты
Ссылки
- CVE-2022-35978
- SUSE Bug 1202423