PT-2021-4111 · Sabnzbd · Sabnzbd

Puzzledsab

·

Published

2021-03-11

·

Updated

2021-05-19

·

CVE-2021-29488

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SABnzbd versions prior to 3.2.1RC1
Description A vulnerability was discovered in SABnzbd that could trick the filesystem.renamer() function into writing downloaded files outside the configured Download Folder via malicious PAR2 files. The issue is related to errors in handling relative directory paths. Exploitation of this vulnerability may allow a remote attacker to impact data integrity using a malicious PAR2 file.
Recommendations For versions prior to 3.2.1RC1, update to version 3.2.1RC1 or later to resolve the issue. As a temporary workaround, consider limiting downloads to NZBs without PAR2 files. Deny write permissions to the SABnzbd process outside areas it must access to perform its job until a patch is applied.

Fix

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04701
CVE-2021-29488
GHSA-JWJ3-WRVF-V3RP

Affected Products

Sabnzbd