-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5075-1 security@debian.org https://www.debian.org/security/ Markus Koschany February 14, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : minetest CVE ID : CVE-2022-24300 CVE-2022-24301 Debian Bug : 1004223 Several vulnerabilities have been discovered in Minetest, a sandbox video game and game creation system. These issues may allow attackers to manipulate game mods and grant them an unfair advantage over other players. These flaws could also be abused for a denial of service attack against a Minetest server or if user input is passed directly to minetest.deserialize without serializing it first, then a malicious user could run Lua code in the server environment. For the oldstable distribution (buster), these problems have been fixed in version 0.4.17.1+repack-1+deb10u1. For the stable distribution (bullseye), these problems have been fixed in version 5.3.0+repack-2.1+deb11u1. We recommend that you upgrade your minetest packages. For the detailed security status of minetest please refer to its security tracker page at: https://security-tracker.debian.org/tracker/minetest Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmIJkPNfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQACgkQ2a0UuVE7 UeTE4A//adF3HOoNzz91UPFMkLqr9a0Uw8I31t2xJGoXhEp7EUUwUz0DDfPwHFTL MA7adZKIwnXGW0fiD9tKafYpZpAl8Vn4++XROhe3cFcILfcoimQ8Yxr/2lo0EJM8 v89jlPNwF3vB1cjorCUdwOgIjKEoBK+522DaBt+FnbDbHRt3W/P5R5HLS8NKmQRX +XSuNBxoYuGzg2MybK5zdiCIVFSj5Bqeyi588Gh1x2J/nbH463xRqMfy757rF0hx Q19yFtpz05a0t4AIB1z2AoF6PIa5hO6TkCu0XDsr/DGDS/2imrBV2XyCawA9x2o2 N/JEnxmVN+4+v8cHsdPPnTi1EUTJvKv1HFWJ3R23h5wwx+oi099lhwlG9xELy8ZA wYiQZsu78IsW6h2qYXPyVkETwrOrCM0LCgyTjWYxGzSMbgA5TlnQpXwqES0cB2Ma Z5lh9Rxbrz/l3jz4+1mVWiP0s2W4kI0xBsFkCR4u1DAyLb2553MYK87f7uWJd6oN GPMLPgoNnH2YK+fnFxsm2cG96Avy7cYtakOmrMD8pxxqZAadoIR26SCiuyf8Wtpn I20XyvokvwnsCf5QTOyZG1yWttIJYr69zIIU9YeSYEGG3ZYkdD+PLDoxMSB1ALNm s9PElsZqfUNLuz0dkRnWrgViti3x4bTGgpCksvi9yks4/h/LyfI= =jHvT -----END PGP SIGNATURE-----