MGASA-2019-0417 - Updated filezilla packages fix security vulnerability

Publication date: 31 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0417.html
Type: security
Affected Mageia releases: 7

Updated filezilla packages fix bugs and a security vulnerability:

Filenames containing double-quotation marks were not escaped correctly
when selected for opening/editing. Depending on the associated program,
parts of the filename could be interpreted as commands.

For other fixes in this update, see the referenced versions log.

References:
- https://bugs.mageia.org/show_bug.cgi?id=25932
- https://filezilla-project.org/versions.php
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/DYM7BZFULYL5BCP2SHUMLBOW2W6CDWPX/

SRPMS:
- 7/core/filezilla-3.46.3-1.mga7
- 7/core/libfilezilla-0.19.3-1.mga7

Mageia 2019-0417: filezilla security update

Updated filezilla packages fix bugs and a security vulnerability: Filenames containing double-quotation marks were not escaped correctly when selected for opening/editing

Summary

Updated filezilla packages fix bugs and a security vulnerability: Filenames containing double-quotation marks were not escaped correctly when selected for opening/editing. Depending on the associated program, parts of the filename could be interpreted as commands.

References

- https://bugs.mageia.org/show_bug.cgi?id=25932

- https://filezilla-project.org/versions.php

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/DYM7BZFULYL5BCP2SHUMLBOW2W6CDWPX/

Resolution

MGASA-2019-0417 - Updated filezilla packages fix security vulnerability

SRPMS

- 7/core/filezilla-3.46.3-1.mga7

- 7/core/libfilezilla-0.19.3-1.mga7

Severity
Publication date: 31 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0417.html
Type: security

Related News