Source: sabnzbdplus Severity: grave Tags: security upstream fixed-upstream X-Debbugs-Cc: [email protected], [email protected]
Hi, two separate vulnerabilities were discovered in sabnzbdplus that involve remote code execution and a directory traversal. No CVEs have been issued yet. * remote code execution vulnerability: in version 5.1.1 and earlier, an attacker who can reach the web interface could bypass authentication on privileged configuration endpoints and, from there, execute arbitrary commands on the system running SABnzbd. https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-rgqj-28c2-gxwp * path traversal vulnerability: in version 5.1.1 and earlier, a maliciously crafted PAR2 or SFV file inside a download could make SABnzbd write files outside the job’s own folder during post-processing, which could be escalated to execute arbitrary commands on the system running SABnzbd. https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-75g3-96fr-7p2r Both issues are fixed in upstream release 5.1.2, the relevant commits are the following: For the remote code execution: https://github.com/sabnzbd/sabnzbd/commit/a0e24089338e4a9b214a439e6dba2ee489195847 https://github.com/sabnzbd/sabnzbd/commit/6525703a94cfdb6c8add5c6f91bc073a7e928ed5 For the path traversal: https://github.com/sabnzbd/sabnzbd/commit/6ddabb5a4599731b00f44162e62f31e291d2b2d0 https://github.com/sabnzbd/sabnzbd/commit/c57af32131216de3e1df3097a0cce06c8c99ceb8 I'll upload the new upstream release to unstable today, and intend to prepare patches for older Debian releases as soon as possible.
pgp_j_C_6F7Pg.pgp
Description: OpenPGP digital signature

