SABnzbd 0.7.11 Release Candidate 2

CPE Details

SABnzbd 0.7.11 Release Candidate 2
0.7.11
2021-05-12
15h45 +00:00
2021-05-12
16h24 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:sabnzbd:sabnzbd:0.7.11:rc2:*:*:*:*:*:*

Informations

Vendor

sabnzbd

Product

sabnzbd

Version

0.7.11

Update

rc2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-29488 2021-05-07 13h00 +00:00 SABnzbd is an open source binary newsreader. A vulnerability was discovered in SABnzbd that could trick the `filesystem.renamer()` function into writing downloaded files outside the configured Download Folder via malicious PAR2 files. A patch was released as part of SABnzbd 3.2.1RC1. As a workaround, limit downloads to NZBs without PAR2 files, deny write permissions to the SABnzbd process outside areas it must access to perform its job, or update to a fixed version.
5.3
Medium