10
CVSSv3

CVE-2022-35978

Published: 15/08/2022 Updated: 17/08/2022
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Minetest is a free open-source voxel game engine with easy modding and game creation. In **single player**, a mod can set a global setting that controls the Lua script loaded to display the main menu. The script is then loaded as soon as the game session is exited. The Lua environment the menu runs in is not sandboxed and can directly interfere with the user's system. There are currently no known workarounds.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

minetest minetest

Vendor Advisories

Debian Bug report logs - #1017548 minetest: CVE-2022-35978 Package: src:minetest; Maintainer for src:minetest is Debian Games Team <pkg-games-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 17 Aug 2022 18:03:02 UTC Severity: grave Tags: security, upstream Found in ver ...