ZeroHour
Ubuntu Security Noticespublished ()ingested

USN-8732-1: Minetest vulnerability

mediumAdvisoryimportance 28
AI summary · glm-5.3-flash

Ubuntu issued USN-8732-1 fixing a Minetest LuaJIT sandbox escape that let malicious mods execute arbitrary code on servers.

Ubuntu Security Notice USN-8732-1 addresses a flaw in Minetest where the Lua sandbox environment was not properly sanitized when using LuaJIT. A malicious mod could escape the sandbox, execute arbitrary code, and gain full file system access on the server. Administrators should update to the patched packages.

  • Ubuntu USN-8732-1 patches Minetest Lua sandbox escape
  • Flaw involves improper sanitization when using LuaJIT
  • Malicious mods could gain full file system access
  • Server compromise possible; update required
Full article

It was discovered that Minetest did not properly sanitize the Lua sandbox environment when using LuaJIT. A malicious mod could escape the sandbox to execute arbitrary code and gain full file system access on the server. An attacker could use this issue to compromise the server.

This source does not provide full text. Read it at ubuntu.com.