Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 8: MGASA-2021-0275 High: Arbitrary Code Injection in Puddletag

mageia
Calendar Grey June 18, 2021
Dist Mageia Esm H88
The latest updates for puddletag address a significant security flaw related to code injection. Here’s what you need to know about the patch and the versions impacted.
The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injectio via the template function, particularly when a vari...

Summary

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injectio via the template function, particularly when a variable property is passed as an argument as it is not sanitized (CVE-2021-23358)

References

- https://bugs.mageia.org/show_bug.cgi?id=29112

- https://www.cve.org/CVERecord?id=CVE-2021-23358

Resolution

SRPMS

- 8/core/puddletag-2.0.2-0.git20210523.1.mga8

Publication date: 18 Jun 2021
URL: https://advisories.mageia.org/MGASA-2021-0269.html
Type: security
CVE: CVE-2021-23358

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here