Bugzilla – Bug 1209285
VUL-0: CVE-2023-28371: stellarium: Arbitrary file write
Last modified: 2024-05-06 08:26:45 UTC
CVE-2023-28371 In Stellarium through 1.2, attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-28371 https://www.cve.org/CVERecord?id=CVE-2023-28371 https://github.com/Stellarium/stellarium/commit/1261f74dc4aa6bbd01ab514343424097f8cf46b7 https://github.com/Stellarium/stellarium/commit/787a894897b7872ae96e6f5804a182210edd5c78 https://github.com/Stellarium/stellarium/commit/eba61df3b38605befcb43687a4c0a159dbc0c5cb
Affected: - openSUSE:Backports:SLE-15-SP4/stellarium - openSUSE:Factory/stellarium
Fixed in Stellarium 23.1 https://stellarium.org/release/2023/03/26/stellarium-23.1.html
openSUSE:Factory is at version 23.1 and is therefore no longer vulnerable to this issue. openSUSE:Backports:SLE-15-SP4:Update received a submit request with the appropriate patches moments ago.
https://build.opensuse.org/request/show/1079198
openSUSE-SU-2023:0097-1: An update that fixes one vulnerability is now available.\n\nCategory: security (important)\nBug References: 1209285\nCVE References: CVE-2023-28371\nJIRA References: \nSources used:\nopenSUSE Backports SLE-15-SP4 (src): stellarium-0.21.2-bp154.2.3.1\n\n
done, closing