DEBIAN-CVE-2021-29488

    Dashboard / Vulnerabilities / DEBIAN-CVE-2021-29488

    DEBIAN-CVE-2021-29488

    Published: 7 May 2021Last Modified: 1 Sept 2026
    Upstream:

    Summary:

    Details: SABnzbd is an open source binary newsreader. A vulnerability was discovered in SABnzbd that could trick the `filesystem.renamer()` function into writing downloaded files outside the configured Download Folder via malicious PAR2 files. A patch was released as part of SABnzbd 3.2.1RC1. As a workaround, limit downloads to NZBs without PAR2 files, deny write permissions to the SABnzbd process outside areas it must access to perform its job, or update to a fixed version.

    Affected packages

    Package

    Name: sabnzbdplus

    Purl: pkg:deb/debian/sabnzbdplus?arch=source&distro=bookworm

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.2.1+dfsg-1

    Affected versions

    0.4.11-1
    0.4.12-1
    0.4.9-1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    DEBIAN-CVE-2021-29488 | CVE-DB