VYPR

rpm package

opensuse/loki&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/loki&distro=openSUSE%20Tumbleweed

Vulnerabilities (2)

  • CVE-2026-39822HigJul 8, 2026
    affected < 3.7.4-1.1fixed 3.7.4-1.1

    On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symb

  • CVE-2024-45337CriDec 12, 2024
    affected < 3.3.2-1.1fixed 3.3.2-1.1

    Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that