Name | CVE-2021-29488 |
Description | SABnzbd is an open source binary newsreader. A vulnerability was discovered in SABnzbd that could trick the `filesystem.renamer()` function into writing downloaded files outside the configured Download Folder via malicious PAR2 files. A patch was released as part of SABnzbd 3.2.1RC1. As a workaround, limit downloads to NZBs without PAR2 files, deny write permissions to the SABnzbd process outside areas it must access to perform its job, or update to a fixed version. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
sabnzbdplus (PTS) | jessie/contrib | 0.7.18-1 | vulnerable |
stretch/contrib | 1.1.1+dfsg-1 | vulnerable | |
buster/contrib | 2.3.6+dfsg-1+deb10u2 | fixed | |
bullseye/contrib | 3.1.1+dfsg-2+deb11u1 | fixed | |
bookworm/contrib | 3.7.1+dfsg-2 | fixed | |
trixie/contrib, sid/contrib | 4.3.3+dfsg-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
sabnzbdplus | source | jessie | (unfixed) | end-of-life | ||
sabnzbdplus | source | stretch | (unfixed) | end-of-life | ||
sabnzbdplus | source | buster | 2.3.6+dfsg-1+deb10u2 | |||
sabnzbdplus | source | bullseye | 3.1.1+dfsg-2+deb11u1 | |||
sabnzbdplus | source | (unstable) | 3.2.1+dfsg-1 |
[stretch] - sabnzbdplus <end-of-life> (Minor issue; contrib not supported)
https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-jwj3-wrvf-v3rp
https://github.com/sabnzbd/sabnzbd/commit/3766ba54026eaa520dbee5b57a2f33d4954fb98b