#991696 Possible CVE-2014-5461 in enigma

Package:
enigma
Source:
enigma
Description:
Game where you control a marble with the mouse
Submitter:
Movses Tovmasyan
Date:
2023-12-15 15:03:02 UTC
Severity:
normal
Tags:
#991696#5
Date:
2021-07-30 11:09:00 UTC
From:
To:
enigma uses the obsolete version of minilua
(single-file port of Lua) which has CVE-2014-5461
Patch attached below.

#991696#10
Date:
2021-08-18 20:51:07 UTC
From:
To:
reassign 991698 enigma

merge 991698 991696

thanks

It does not make sense to report the bug against the *data* package. Its
in the binary, not the data. No need to report it twice.

Also, why use a screenshot of the diff, and not just the diff directly,
wtf? Why would you make a screenshot of a diff in the first place?

Clearly this should be fixed, but the security implications are very
limited.


The enigma package currently is not maintained. A new upstream version
exists.

Someone has indicated the intent to adopt the package, but not much has
happened so far: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=902855


Am 30.07.21 um 13:12 schrieb Movses Tovmasyan:

#991696#13
Date:
2023-12-10 16:19:39 UTC
From:
To:
Only #991696 makes sense.
This one is merely a confusing duplicate.