{"id":"openSUSE-SU-2023:0001-1","summary":"Security update for minetest","details":"This update for minetest fixes the following issues:\n\nUpdate to version 5.6.0\n\n  * Fix CVE-2022-35978 ( boo#1202423 ): Mod scripts can escape sandbox in single player mode\n  * `name` in game.conf is deprecated for the game title, use `title` instead\n  * Add depth sorting for node faces\n  * Various bug fixes\n  * Full changes: https://dev.minetest.net/Changelog#5.5.0_.E2.86.92_5.6.0\n\n- Introduced mbranch-protection=none CXX flag to resolve boo#1193141\n  (aarch64).\n\nUpdate to version 5.5.0 & 5.5.1:\n\n  * Full log for version 5.5.0: https://dev.minetest.net/Changelog#5.4.0_.E2.86.92_5.5.0\n  * This release switches from Irrlicht to our own fork called IrrlichtMt.\n  * Full log for version 5.5.1: https://dev.minetest.net/Changelog#5.5.0_.E2.86.92_5.5.1\n  * This is a maintenance release based on 5.5.0, it contains bugfixes but no new features.\n\n- Added hardening to systemd service(s) (boo#1181400). \n\n- Update to version 5.4.1:\n  * This is a maintenance release based on 5.4.0,\n    it contains bugfixes but no new features.\n\n- Update to version 5.4.0\n  * Full log: https://dev.minetest.net/Changelog#5.3.0_.E2.86.92_5.4.0\n  * Removed support for bumpmapping, generated normal maps\n    and parallax occlusion\n  * By default, the crosshair will now change to an 'X' when\n    pointing to objects\n  * Prevent players accessing inventories of other players\n  * Prevent interacting with items out of the hotbar\n  * Prevent players from being able to modify ItemStack meta\n\n- Update to version 5.3.0. \n  (see https://dev.minetest.net/Changelog#5.2.0_.E2.86.92_5.3.0)\n  * Formspec improvements, including a scrolling GUI element\n  * Performance improvements to the Server and API\n  * Many bug fixes and small features\n- Now requires desktop-file-utils version \u003e= 0.25.\n","modified":"2026-02-04T02:54:27.311104Z","published":"2023-01-03T09:15:50Z","related":["CVE-2022-35978"],"upstream":["CVE-2022-35978"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6BEL53A6YRA752TFXGECQDT4XJ7UK6P5/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181400"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193141"},{"type":"REPORT","url":"https://bugzilla.suse.com/1202423"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-35978"}],"affected":[{"package":{"name":"minetest","ecosystem":"SUSE:Package Hub 15 SP3","purl":"pkg:rpm/suse/minetest&distro=SUSE%20Package%20Hub%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.6.0-bp154.2.3.5"}]}],"ecosystem_specific":{"binaries":[{"minetest":"5.6.0-bp154.2.3.5","minetest-data":"5.6.0-bp154.2.3.5","minetest-lang":"5.6.0-bp154.2.3.5","minetestserver":"5.6.0-bp154.2.3.5"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0001-1.json"}},{"package":{"name":"minetest","ecosystem":"SUSE:Package Hub 15 SP4","purl":"pkg:rpm/suse/minetest&distro=SUSE%20Package%20Hub%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.6.0-bp154.2.3.5"}]}],"ecosystem_specific":{"binaries":[{"minetest-data":"5.6.0-bp154.2.3.5","minetest-lang":"5.6.0-bp154.2.3.5","minetestserver":"5.6.0-bp154.2.3.5","minetest":"5.6.0-bp154.2.3.5"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0001-1.json"}},{"package":{"name":"minetest","ecosystem":"openSUSE:Leap 15.3","purl":"pkg:rpm/opensuse/minetest&distro=openSUSE%20Leap%2015.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.6.0-bp154.2.3.5"}]}],"ecosystem_specific":{"binaries":[{"minetest-lang":"5.6.0-bp154.2.3.5","minetestserver":"5.6.0-bp154.2.3.5","minetest":"5.6.0-bp154.2.3.5","minetest-data":"5.6.0-bp154.2.3.5"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0001-1.json"}},{"package":{"name":"minetest","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/minetest&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.6.0-bp154.2.3.5"}]}],"ecosystem_specific":{"binaries":[{"minetest-data":"5.6.0-bp154.2.3.5","minetest-lang":"5.6.0-bp154.2.3.5","minetestserver":"5.6.0-bp154.2.3.5","minetest":"5.6.0-bp154.2.3.5"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0001-1.json"}}],"schema_version":"1.7.3"}