UBUNTU-CVE-2022-24300
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-24300
Summary:
Details: Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection.
References: https://ubuntu.com/security/CVE-2022-24300, https://github.com/minetest/minetest/security/advisories/GHSA-hwj2-xf72-r4cf, https://github.com/minetest/minetest/security/advisories/GHSA-7q63-4fq2-hqcr, https://github.com/minetest/minetest/commit/8d6a0b917ce1e7f4f1017835af0ca76e79c98c38, https://github.com/minetest/minetest/commit/b5956bde259faa240a81060ff4e598e25ad52dae, https://bugs.debian.org/1004223, https://www.cve.org/CVERecord?id=CVE-2022-24300
Affected packages
Package
Name: minetest
Purl: pkg:deb/ubuntu/minetest?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
