Source: sabnzbdplus
Severity: grave
Tags: security patch upstream fixed-upstream
X-Debbugs-Cc: [email protected], [email protected]

Hi,

a vulnerability was discovered in sabnzbdplus that allows any client
with access to the password-protected web interface to obtain an
authenticated session without knowing the username or password.

Affected versions are all since 3.0.0 through 5.1.0; for Debian that
translates to every release since bullseye. Fixed in upstream release
5.1.1, meanwhile uploaded to unstable as 5.1.1+dfsg-1.

CVE: [not yet]
Github: 
https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-xrfq-jhgh-wqch
Fix: 
https://github.com/sabnzbd/sabnzbd/commit/9a12300877a38becda23dada37fd4f9c488801a5

Patches (source debdiff) for the sabnzbdplus package in bookworm and
trixie are attached, and published in the {bookworm,trixie}-security
branches in the package's VCS on salsa. Both have been verified to
build, install, run, and fix the security issue.

Attachment: sabnzbdplus_3.7.1+dfsg-2+deb12u1.debdiff
Description: Binary data

Attachment: sabnzbdplus_4.5.0+dfsg-1+deb13u1.debdiff
Description: Binary data

Attachment: pgpMniD8BDzh2.pgp
Description: OpenPGP digital signature

Reply via email to