Patching Remote Code Execution Flaw for Unity 2017.1.0f3

I received an email about a Remote Code Execution flaw in the Editor, discussed at Unity's Protection Policies For Its Creators | Unity Security.

I looked at what versions of Unity there were for which I could download the patch. I have Unity version 2017.1.0f3 Personal. The closest version listed for the patch is 2017.1.0p4. Is this the correct version for the patch – does the p4 signify it is version 4 of a patch – for any 2017.1 version of Unity?

Changelog

Hello datahead8888 :smile:
I am using unity 2017.1.0f3 i can not build to apk file you have error ? Please help me. I have piture error please view it

Yep, the latest patch for each version listed in the security bulletin fixes the vulnerability.

Start a new thread please, this is not even remotely on topic.

Ok thanks datahead8888

Why didn’t they just allow you to click the update button in Unity for the fix or change the newest download build? I was using Unity 5.3 and downloaded 2017 from the site thinking that would be the newest version. I hope this patch is the reason for so many crashes since updating to 2017 as it probably crashes once an hour now.

The security vulnerability patch is unlikely to address what are probably unrelated crashes you’re experiencing.

very much this… why is a vulnerable version still being pushed to users from the main download? First step of sorting any problem is stopping it getting worse; having the main download page push out a vulnerable version of unity is just crazy.

“Welcome to unity new user! Here to make your first game are you? well, have a security flaw and confusing hoops to jump through with no information to fix it… sincerely unity team” :stuck_out_tongue:

1 Like

^ +1
wtf unity?