NNCP could allow unintended access to files.. ========================================================================== Ubuntu Security Notice USN-8359-1 June 01, 2026 nncp vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: NNCP could allow unintended access to files. Software Description: - nncp: package facilitating secure store-and-forward file and mail exchange Details: It was discovered that NNCP did not properly sanitize file paths in packet data during file requesting and file saving operations. A remote attacker could possibly use this issue to read or write arbitrary files outside of the intended directory. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 nncp 8.11.0-4+deb13u1build0.25.10.1 Ubuntu 24.04 LTS nncp 8.10.0-8ubuntu0.3+esm3 Available with Ubuntu Pro Ubuntu 22.04 LTS nncp 8.5.0-1ubuntu0.1+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8359-1 CVE-2025-60020 Package Information: https://launchpad.net/ubuntu/+source/nncp/8.11.0-4+deb13u1build0.25.10.1 . NNCP flaw in Ubuntu allows unauthorized file access. Update to protect against potential remote attacks now.. Ubuntu NNCP security Threat Protection File Access Remote Attacks. . Severity: Important. LinuxSecurity.com Team
Eugene Medvedev discovered that nncp, a package facilitating secure store-and-forward file and mail exchange, was susceptible to path traversal with the freq and file commands. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-6012-1
Get the latest Linux and open source security news straight to your inbox.