security advisorydebianimportant Eugene Medvedev discovered that nncp, a package facilitating secure store-and-forward file and mail exchange, was susceptible to path traversal with the freq and file commands. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-6012-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso September 26, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : nncp CVE ID : CVE-2025-60020 Debian Bug : 1115848 Eugene Medvedev discovered that nncp, a package facilitating secure store-and-forward file and mail exchange, was susceptible to path traversal with the freq and file commands. For the oldstable distribution (bookworm), this problem has been fixed in version 8.8.2-3+deb12u1. For the stable distribution (trixie), this problem has been fixed in version 8.11.0-4+deb13u1. We recommend that you upgrade your nncp packages. For the detailed security status of nncp please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/nncp Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Upgrade nncp to address important path traversal issue found in DSA-6012-1. Stay secure with Debian updates.. nncp security, path traversal vulnerability, Debian advisory, file exchange protection. . Severity: Important. LinuxSecurity.com Team
Sep 26, 2025 •Important Debian