MGASA-2019-0417

Source
https://advisories.mageia.org/MGASA-2019-0417.html
Import Source
https://advisories.mageia.org/MGASA-2019-0417.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0417
Published
2019-12-31T16:51:17Z
Modified
2026-04-16T04:26:08.281335Z
Summary
Updated filezilla packages fix security vulnerability
Details

Updated filezilla packages fix bugs and a security vulnerability:

Filenames containing double-quotation marks were not escaped correctly when selected for opening/editing. Depending on the associated program, parts of the filename could be interpreted as commands.

For other fixes in this update, see the referenced versions log.

References
Credits

Affected packages

Mageia:7 / filezilla

Package

Name
filezilla
Purl
pkg:rpm/mageia/filezilla?arch=source&distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.46.3-1.mga7

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2019-0417.json"

Mageia:7 / libfilezilla

Package

Name
libfilezilla
Purl
pkg:rpm/mageia/libfilezilla?arch=source&distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.19.3-1.mga7

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2019-0417.json"