CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file when creating a new record.
{ "binaries": [ { "binary_version": "3.0.2-3", "binary_name": "hamster-applet" }, { "binary_version": "3.0.2-3", "binary_name": "hamster-time-tracker" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-36250.json"
{ "binaries": [ { "binary_version": "3.0.3-1ubuntu1", "binary_name": "hamster-time-tracker" } ] }
{ "binaries": [ { "binary_version": "3.0.3-3", "binary_name": "hamster-time-tracker" } ] }