[Question] Remote Code Execution Flaw?

Hello All,

Today I received an email supposedly from Unity saying the following:

“Unity has identified a Remote Code Execution flaw in the Editor and we’re rolling out a critical security patch to remediate this issue…”

Being the somewhat paranoid type, and not being able to find out anything talking about this on the main Unity site, I am wondering if this is a legitimate email and whether I should click on the link to download the appropriate patch.

Confirmation would be much appreciated.

Thankyou and Regards.

All details there.

1 Like

Thanks, I really appreciate the response that puts my mind at ease.

I just wanted to be sure that the email wasn’t bogus and the link genuine!

Cheers.

1 Like

I have a question on it, why on earth do I have to download the entire unity system again just to do a security patch, helloooooo patching just whats needed been around since the 80’s get with it.

Totally agree! And I need a complete re-install, as there is no patch for 5.5.1 which i use, so, I have to download a new version 5.5.4 (w/ patch) - and this is going to eat into my free space on my limited hard drive.

Although it seems to be happening with games as well - I think I remember the patch for Streetfighter V being larger than the original game, and last night I needed a 12GB “patch” for two new characters and two new stages with “For Honour” - a 12GB patch!!!

They are working on it! Packman, in 2017.2 will also help make things more modular too.

Can someone explain exactly what can happen if Ido not appy the patch in a worse case?

Not until the period of responsible disclosure has passed. Unity will then tell everyone what it is. I could tell you to hop on reddit or whatever though.

Today (3/4/2019) I received an email with this notification. Presumably this alert is a scam, coming 2 years after the original alert. The start of the email is, “Hello there,” . Wouldn’t an official email have my user name?

Unfortunately not a scam. If you visited the link posted just a few posts above (https://unity3d.com/security) then you would see that it is real.

Kind of unnecessary considering it would be an email going to everyone. I do not think whether an email has your name or not is indicative of a scam, it is not hard to find a username of even real name for a lot of people. Usually that is given away by the sender being a scam email or poor grammar or one of a number of different factors.

So I’m using 2018.3.0f2 which says it’s the latest version. That means I don’t need the patch right?

I think this is the patched version here:

  • [3] 2018.3.7f1 (Win), size=570,279kB, md5=6fcde1045cc4af7f84ba4f820f5db868

Found here:

Oh right. So it’s a new version. I thought it was just going to be an actual small patch to download.

Im closing this thread. This is two separate security issues being discussed here and its confusing. Please visit Unity's Protection Policies For Its Creators | Unity Security