MGASA-2017-0480

Source
https://advisories.mageia.org/MGASA-2017-0480.html
Import Source
https://advisories.mageia.org/MGASA-2017-0480.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2017-0480
Related
Published
2017-12-31T15:14:43Z
Modified
2017-12-31T14:49:09Z
Summary
Updated shotwell packages fix security vulnerability
Details

It was discovered that Shotwell is vulnerable to an information disclosure in the web publishing plugins resulting in potential password and oauth token plaintext transmission (CVE-2017-1000024).

References
Credits

Affected packages

Mageia:5 / shotwell

Package

Name
shotwell
Purl
pkg:rpm/mageia/shotwell?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.22.1-0.20160310.1.1.mga5

Ecosystem specific

{
    "section": "core"
}