-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 13 Feb 2022 21:46:40 CET Source: minetest Architecture: source Version: 0.4.17.1+repack-1+deb10u1 Distribution: buster-security Urgency: high Maintainer: Debian Games Team <pkg-games-devel@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Checksums-Sha1: 337b04d0d14f3626a9b4e1b4c6def3a53241881e 2746 minetest_0.4.17.1+repack-1+deb10u1.dsc 946d26b0ef0e97759eec4516dbf29349f3e50265 8930830 minetest_0.4.17.1+repack.orig.tar.gz bf4b4f6a81a70c37425c076c072c7be5fa0b0d7e 38496 minetest_0.4.17.1+repack-1+deb10u1.debian.tar.xz edccf5da8de3d1eafd1a44d7574dcfa38b57ff93 13214 minetest_0.4.17.1+repack-1+deb10u1_amd64.buildinfo Checksums-Sha256: a99309b7e51f91499de981b2f2bb33e4aabb81d64196babdc1275454c4c7bcee 2746 minetest_0.4.17.1+repack-1+deb10u1.dsc d77c483e983b764056a1edc507933dfc9aa2c95b24daba14b45ff3ad5153d6c6 8930830 minetest_0.4.17.1+repack.orig.tar.gz eb0ce463e94cbe2e97ab284d5c53cb34003061452b873e35115a26f666df0b41 38496 minetest_0.4.17.1+repack-1+deb10u1.debian.tar.xz a30995ba016acf46f495817eb310e0281b2129bffa9122cecabcb67383dcbfeb 13214 minetest_0.4.17.1+repack-1+deb10u1_amd64.buildinfo Closes: 1004223 Changes: minetest (0.4.17.1+repack-1+deb10u1) buster-security; urgency=high . * Fix CVE-2022-24300 and CVE-2022-24301: Several vulnerabilities have been discovered in Minetest. These issues may allow attackers to manipulate game mods and grant them an unfair advantage over other players. These flaws could also be abused for a denial of service attack or if user input is passed directly to minetest.deserialize without serializing it first, then a malicious user could run Lua code in the server environment. (Closes: #1004223) Files: 324f5712864c65077b7fd1304e05eef2 2746 games optional minetest_0.4.17.1+repack-1+deb10u1.dsc 7681cd511b845020cdd584214c0377e6 8930830 games optional minetest_0.4.17.1+repack.orig.tar.gz b26b932e3cf584fc6ad14b5e25fd15fb 38496 games optional minetest_0.4.17.1+repack-1+deb10u1.debian.tar.xz 4478bd2c7c1773ed2207128c3b222e9a 13214 games optional minetest_0.4.17.1+repack-1+deb10u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmIJbv9fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkJ+YQAKnCDNw9Lpl4LFVtRFHSMLoA5JupcHaLSWDi RnygE5R1OBwIxZ3Sta7qYdgs0P/BLwa3l0aC3wIFUinCwi7Q2iEaxzTTVioLgcR+ Z/P5UmhCdDqTAzh+2vKmJoRBX7HTPRCyLh7EoDowhZjLi9MrF5TQBJ/p4lDxioaX s6WZ1vX4+d1IdtCaQq6KBZuJ5UNsxiIIwffShC+nZO/jAAdSvCsaymQX29YJVN/j VKJ9wvjXKMgO9dIAR76HQTO0o/mcocd1pO2Gwpl9UfEW99YCxplBYElnpyX8IY7U icRg6/OzHCAlGvPyLZzsuFz9Ou7aTsaHi0tw+SQwP3LMtM1ugvdK5k0xrz7spQUF BW3aU12cWDxdVQAGQ1+W1ZuA+s0IgcZvK1xrc+HncGPIYUbUg3u5Dfyv05WdEjvo zGhMszb4JBNBnA1w6PA237ZqgviQB0Yb/Euuh9TyeeoSldk0v4+PHHsuXQnHjIt1 1rrOu3FlgJ4jtr+bX22FzBsTlprtJyde1Nk5BFsO07ur+Hebbp8smIwb7CZRuGV7 sJdGjvCXlDU+eLbUjgo5ah2TX2uxwSBtuiUQH6Svc3Vgi2Pnfeynt/DB1OaEg4et WciMrf+oDpmWFcMGBrqzBtppuwHZ+3WOjRmNNzzFs8msjltNUbpnj1Ga3Nw2yM0B 97eOzI9h =Zu1+ -----END PGP SIGNATURE-----