From a8f97908f4480a9712a58f19cfe3dc3ebda24e3f Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Fri, 5 Jul 2024 17:31:39 +0000 Subject: [ GLSA 202407-18 ] Stellarium: Arbitrary File Write Bug: https://bugs.gentoo.org/905300 Signed-off-by: GLSAMaker Signed-off-by: Hans de Graaff --- glsa-202407-18.xml | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 glsa-202407-18.xml diff --git a/glsa-202407-18.xml b/glsa-202407-18.xml new file mode 100644 index 00000000..ea2c242f --- /dev/null +++ b/glsa-202407-18.xml @@ -0,0 +1,42 @@ + + + + Stellarium: Arbitrary File Write + A vulnerability has been discovered in Stellarium, which can lead to arbitrary file writes. + stellarium + 2024-07-05 + 2024-07-05 + 905300 + local and remote + + + 23.1 + 23.1 + + + +

Stellarium is a free open source planetarium for your computer. It shows a realistic sky in 3D, just like what you see with the naked eye, binoculars or a telescope.

+
+ +

A vulnerability has been discovered in Stellarium. Please review the CVE identifier referenced below for details.

+
+ +

Attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal.

+
+ +

There is no known workaround at this time.

+
+ +

All Stellarium users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sci-astronomy/stellarium-23.1" + +
+ + CVE-2023-28371 + + graaff + graaff +
\ No newline at end of file -- cgit v1.2.3-65-gdbad