Advisories ยป MGASA-2020-0394

Updated claws-mail packages fix a security vulnerability

Publication date: 24 Oct 2020
Type: security
Affected Mageia releases : 7

Description

Shielded template's |program{} and |attach_program{} so that the
command-line that is executed does not allow sequencing such as
with && || ;, preventing possible execution of nasty, or at least
unexpected, commands. (No CVE).
                

References

SRPMS

7/core