Source: sabnzbdplus
Severity: grave
Tags: security upstream fixed-upstream
X-Debbugs-Cc: [email protected], [email protected]

Hi,

two further vulnerabilities were discovered in sabnzbd that allow
unauthenticated API access respectively remote code execution. Both
issues are fixed in upstream release 5.1.3. No CVEs have been issued
yet.

* __wrapped__ dispatch bypass allows unauthenticated API access.
  https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-q326-jpxx-jmjc

* PAR2 symlink bypass allows pickle remote code execution.
  https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-mjwj-v5mr-cmcg


Upstream provides an overview of all the recent vulnerability at
https://sabnzbd.org/wiki/extra/5.1-vulnerabilities.html

I'll upload the new upstream release to unstable today, and intend to
prepare patches for backports and older Debian releases as soon as
possible.

Attachment: pgpHxDAgVe6ir.pgp
Description: OpenPGP digital signature

Reply via email to