Source: sabnzbdplus Severity: grave Tags: security patch upstream fixed-upstream X-Debbugs-Cc: [email protected], [email protected]
Hi, a vulnerability was discovered in sabnzbdplus that allows any client with access to the password-protected web interface to obtain an authenticated session without knowing the username or password. Affected versions are all since 3.0.0 through 5.1.0; for Debian that translates to every release since bullseye. Fixed in upstream release 5.1.1, meanwhile uploaded to unstable as 5.1.1+dfsg-1. CVE: [not yet] Github: https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-xrfq-jhgh-wqch Fix: https://github.com/sabnzbd/sabnzbd/commit/9a12300877a38becda23dada37fd4f9c488801a5 Patches (source debdiff) for the sabnzbdplus package in bookworm and trixie are attached, and published in the {bookworm,trixie}-security branches in the package's VCS on salsa. Both have been verified to build, install, run, and fix the security issue.
sabnzbdplus_3.7.1+dfsg-2+deb12u1.debdiff
Description: Binary data
sabnzbdplus_4.5.0+dfsg-1+deb13u1.debdiff
Description: Binary data
pgpMniD8BDzh2.pgp
Description: OpenPGP digital signature

