Please read this before reporting a bug:
http://wiki.archlinux.org/index.php/Reporting_Bug_Guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
Attached to Project:
Community Packages
Opened by Jonas Witschel (diabonas) - Wednesday, 05 May 2021, 12:24 GMT
Last edited by Jonas Witschel (diabonas) - Tuesday, 20 July 2021, 19:21 GMT
|
DetailsSummary The package impacket is vulnerable to directory traversal via CVE-2021-31800.
Guidance Applying the commit referenced below fixes the issue. The mentioned pull request also contains a second commit (https://github.com/SecureAuthCorp/impacket/commit/6688da5d97592269aae72b3a00dc1ab186c0b33d) which changes some error response codes, but that doesn't seem to be security-related and is therefore not strictly necessary to fix the issue.
References
https://security.archlinux.org/AVG-1916 |
This task depends upon
Closed by Jonas Witschel (diabonas)
Tuesday, 20 July 2021, 19:21 GMT
Reason for closing: Fixed
Additional comments about closing: impacket 0.9.23-1