Bug#975370: xdg-utils: CVE-2020-27748: local file inclusion vulnerability

2025-05-10 Thread Salvatore Bonaccorso
Hi, Upstream has merged fixes for this issue: https://gitlab.freedesktop.org/xdg/xdg-utils/-/merge_requests/89 Regards, Salvatore

Bug#975370: xdg-utils: CVE-2020-27748: local file inclusion vulnerability

2020-12-30 Thread Nicholas Guriev
On Вс, 2020-12-06 at 13:36 -0500, John Scott wrote: > On Sunday, November 29, 2020 1:40:17 AM EST Nicholas Guriev wrote: > > Proposed change offers to completely remove `attach` parameter. I don't > > like to break existing features. > It appears that it only removes the attach parameter for Thunde

Bug#975370: xdg-utils: CVE-2020-27748: local file inclusion vulnerability

2020-12-06 Thread John Scott
On Sunday, November 29, 2020 1:40:17 AM EST Nicholas Guriev wrote: > Proposed change offers to completely remove `attach` parameter. I don't > like to break existing features. It appears that it only removes the attach parameter for Thunderbird in that commit. Perhaps that's because other mail cli

Bug#975370: xdg-utils: CVE-2020-27748: local file inclusion vulnerability

2020-11-21 Thread Salvatore Bonaccorso
Source: xdg-utils Version: 1.1.3-2 Severity: important Tags: security upstream Forwarded: https://gitlab.freedesktop.org/xdg/xdg-utils/-/issues/177 X-Debbugs-Cc: car...@debian.org, Debian Security Team Control: found -1 1.1.3-1+deb10u1 Control: found -1 1.1.3-1 Hi, The following vulnerability wa