[Bug 1204409] VUL-0: CVE-2022-41751: jhead: arbitrary OS commands by placing them in a JPEG filename
https://bugzilla.suse.com/show_bug.cgi?id=1204409 https://bugzilla.suse.com/show_bug.cgi?id=1204409#c2 David Anes <david.anes@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |david.anes@suse.com, | |sbrabec@suse.com Flags| |needinfo?(sbrabec@suse.com) --- Comment #2 from David Anes <david.anes@suse.com> --- I fixed it on all codestreams. The following 2 patches were needed: * https://github.com/Matthias-Wandel/jhead/pull/57 * https://github.com/Matthias-Wandel/jhead/commit/ec67262b8e5a4b05d8ad6898a09f... Codestream Vers. Request ---------------------------------------------------------------------- Backports:SLE-15-SP3:Update 3.00 https://build.opensuse.org/request/show/1031582 Backports:SLE-15-SP4:Update 3.06.0.1 https://build.opensuse.org/request/show/1031581 Factory 3.06.0.1 https://build.opensuse.org/request/show/1031580 Feel free to send to security as you review, Standa. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com