CVE-2017-1000024

NameCVE-2017-1000024
DescriptionShotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potential password and oauth token plaintext transmission
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
shotwell (PTS)jessie0.20.1-1vulnerable
stretch0.25.4+really0.24.5-0.1fixed
buster, sid0.28.4-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
shotwellsource(unstable)0.25.4+really0.24.5-0.1unimportant

Search for package or bug name: Reporting problems