oss-sec mailing list archives

Requesting CVE for calibre file disclosure


From: Martin Pitt <mpitt () debian org>
Date: Sun, 29 Jan 2017 17:34:44 +0100

Hello all,

Calibre 2.75 fixed what looks like a local data disclosure vulnerability:

  https://github.com/kovidgoyal/calibre/commit/3a89718664cb8c

@Kovid: Would you mind making the original Launchpad bug
https://launchpad.net/bugs/1651728 public?

@osssec: Can you please assign a CVE on this one?

Thanks to Antoine for pointing this out, this deserves an update in stable
distro releases.

Martin

Attachment: signature.asc
Description:


Current thread: