CVE-2021-29488
Creation of files outside the Download Folder through malicious PAR2 files
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SABnzbd is an open source binary newsreader. A vulnerability was discovered in SABnzbd that could trick the `filesystem.renamer()` function into writing downloaded files outside the configured Download Folder via malicious PAR2 files. A patch was released as part of SABnzbd 3.2.1RC1. As a workaround, limit downloads to NZBs without PAR2 files, deny write permissions to the SABnzbd process outside areas it must access to perform its job, or update to a fixed version.
SABnzbd es un lector de noticias binario de código abierto. Se detectó una vulnerabilidad en SABnzbd que podría engañar a la función "filesystem.renamer()" para escribir archivos descargados fuera de la carpeta de descarga configurada por medio de archivos PAR2 maliciosos. Un parche se lanzó como parte de SABnzbd versión 3.2.1RC1. Como solución alternativa, el límite descargas a los NZB sin archivos PAR2, niegue los permisos de escritura al proceso SABnzbd fuera de las áreas a las que debe acceder para llevar a cabo su trabajo o actualizar a una versión fija
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-03-30 CVE Reserved
- 2021-05-07 CVE Published
- 2024-01-21 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-23: Relative Path Traversal
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-jwj3-wrvf-v3rp | 2021-05-19 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sabnzbd Search vendor "Sabnzbd" | Sabnzbd Search vendor "Sabnzbd" for product "Sabnzbd" | < 3.0.0 Search vendor "Sabnzbd" for product "Sabnzbd" and version " < 3.0.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Sabnzbd Search vendor "Sabnzbd" | Sabnzbd Search vendor "Sabnzbd" for product "Sabnzbd" | < 3.2.1 Search vendor "Sabnzbd" for product "Sabnzbd" and version " < 3.2.1" | - |
Affected
| in | Apple Search vendor "Apple" | Macos Search vendor "Apple" for product "Macos" | - | - |
Safe
|
Sabnzbd Search vendor "Sabnzbd" | Sabnzbd Search vendor "Sabnzbd" for product "Sabnzbd" | < 3.2.1 Search vendor "Sabnzbd" for product "Sabnzbd" and version " < 3.2.1" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|