Advisories ยป MGASA-2021-0401

Updated dino packages fix security vulnerability

Publication date: 14 Aug 2021
Modification date: 14 Aug 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-33896

Description

Updated dino packages fix security vulnerability:

Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal
(only for creation of new files) via URI-encoded path separators
(CVE-2021-33896).
                

References

SRPMS

8/core