TEMP-1147154-ECE4C7

NameTEMP-1147154-ECE4C7
DescriptionGHSA-mjwj-v5mr-cmcg: PAR2 symlink bypass allows pickle remote code execution.
SourceAutomatically generated temporary name. Not for external reference.
Debian Bugs1147154

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
sabnzbdplus (PTS)bookworm/contrib3.7.1+dfsg-2vulnerable
trixie/contrib4.5.0+dfsg-1+deb13u1vulnerable
trixie/contrib (security)4.5.0+dfsg-1+deb13u2fixed
forky/contrib, sid/contrib5.1.3+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
sabnzbdplussourcetrixie4.5.0+dfsg-1+deb13u2
sabnzbdplussource(unstable)5.1.3+dfsg-11147154

Notes

https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-mjwj-v5mr-cmcg

Search for package or bug name: Reporting problems