Source: sabnzbdplus
Severity: grave
Tags: security upstream fixed-upstream
X-Debbugs-Cc: [email protected], [email protected]

Hi,

two separate vulnerabilities were discovered in sabnzbdplus that
involve remote code execution and a directory traversal. No CVEs have
been issued yet.

* remote code execution vulnerability: in version 5.1.1 and earlier,
  an attacker who can reach the web interface could bypass
  authentication on privileged configuration endpoints and, from
  there, execute arbitrary commands on the system running SABnzbd.
  https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-rgqj-28c2-gxwp

* path traversal vulnerability: in version 5.1.1 and earlier, a
  maliciously crafted PAR2 or SFV file inside a download could make
  SABnzbd write files outside the job’s own folder during
  post-processing, which could be escalated to execute arbitrary
  commands on the system running SABnzbd.
  https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-75g3-96fr-7p2r


Both issues are fixed in upstream release 5.1.2, the relevant commits
are the following:

For the remote code execution:
https://github.com/sabnzbd/sabnzbd/commit/a0e24089338e4a9b214a439e6dba2ee489195847
https://github.com/sabnzbd/sabnzbd/commit/6525703a94cfdb6c8add5c6f91bc073a7e928ed5

For the path traversal:
https://github.com/sabnzbd/sabnzbd/commit/6ddabb5a4599731b00f44162e62f31e291d2b2d0
https://github.com/sabnzbd/sabnzbd/commit/c57af32131216de3e1df3097a0cce06c8c99ceb8


I'll upload the new upstream release to unstable today, and intend to
prepare patches for older Debian releases as soon as possible.

Attachment: pgp_j_C_6F7Pg.pgp
Description: OpenPGP digital signature

Reply via email to