Dʒɛmɪni security announcement

A couple of days ago I've found and fix a path traversal issue in the dezhemini gemini server software. A specially crafted URL will allow an attacker to read arbitrary files from the host file system.

The issue is fixed in commit 2dba1ee1c875b07ca2e04f8bf2d03bfc5b2afc5f. All versions prior to this commit are vulnerable to this type of intrusion.

Please upgrade as soon as possible.

--

📅 2021-05-13

🏷 dʒɛmɪni, announcement

📧 hello@rwv.io

CC BY-NC-SA 4.0

Proxy Information
Original URL
gemini://rwv.io/2021-05-13-dezhemini-security-announcement.gmi
Status Code
Success (20)
Meta
text/gemini; lang=en
Capsule Response Time
192.78439 milliseconds
Gemini-to-HTML Time
0.194125 milliseconds

This content has been proxied by September (ba2dc).