CVE-2025-60020

NameCVE-2025-60020
Descriptionnncp before 8.12.0 allows path traversal (for reading or writing) during freqing and file saving via a crafted path in packet data.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1115848

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nncp (PTS)bookworm8.8.2-3vulnerable
forky, trixie8.11.0-4vulnerable
sid8.12.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nncpsource(unstable)8.12.1-11115848

Notes

http://www.nncpgo.org/Release-8_005f12_005f0.html
http://lists.cypherpunks.su/archive/nncp-devel/CAO-d-4riai9EZx4gVfekow-BCtTn07k8BB1ZdsopPVw=scWD1A@mail.gmail.com/T/#md678a00df1020bb811f47f42ef33c54b789cddd7

Search for package or bug name: Reporting problems