CVE-2017-1000024

NameCVE-2017-1000024
DescriptionShotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potential password and oauth token plaintext transmission
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
shotwell (PTS)jessie0.20.1-1vulnerable
stretch0.25.4+really0.24.5-0.1fixed
buster0.30.1-1fixed
bullseye, sid0.30.7-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
shotwellsource(unstable)0.25.4+really0.24.5-0.1unimportant

Search for package or bug name: Reporting problems