Bug ID 1202423
Summary VUL-0: CVE-2022-35978: minetest: Mod scripts can escape sandbox in single player
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.4
Hardware Other
URL https://smash.suse.de/issue/339900/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Security
Assignee dap.darkness@gmail.com
Reporter cathy.hu@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2022-35978

Minetest is a free open-source voxel game engine with easy modding and game
creation. In **single player**, a mod can set a global setting that controls
the
Lua script loaded to display the main menu. The script is then loaded as soon
as
the game session is exited. The Lua environment the menu runs in is not
sandboxed and can directly interfere with the user's system. There are
currently
no known workarounds.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-35978
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-35978
https://github.com/minetest/minetest/commit/da71e86633d0b27cd02d7aac9fdac625d141ca13
https://github.com/minetest/minetest/security/advisories/GHSA-663q-pcjw-27cc
https://dev.minetest.net/Changelog#5.5.0_.E2.86.92_5.6.0


You are receiving this mail because: