<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T19:55:16.095986+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-210120</id>
    <title>EUVD-2026-210120</title>
    <updated>2026-10-10T19:55:16.099262+00:00</updated>
    <content>EUVD-2026-210120</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-210120"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-32698</id>
    <title>fkie_cve-2023-32698</title>
    <updated>2026-10-10T19:55:16.099299+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packaged 
the files (without extra config for enforcing it’s own permissions) files could go out with bad permissions (chmod 666 or 777). Anyone using nfpm for creating packages without checking/setting file permissions before packaging could result in bad permissions for files/folders.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-32698"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w7jw-q4fg-qc4c</id>
    <title>GHSA-w7jw-q4fg-qc4c — nfpm has incorrect default permissions</title>
    <updated>2026-10-10T19:55:16.099334+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/goreleaser/nfpm/v2, Go: github.com/goreleaser/nfpm</p>
<p>### Summary
When building packages directly from source control, file permissions on the checked-in files are not maintained.</p>
<p>### Details
When building packages directly from source control, file permissions on the checked-in files are not maintained. When nfpm packaged the files (without extra config for enforcing its own permissions) files could go out with bad permissions (chmod 666 or 777).</p>
<p>### PoC
Create a default nfpm structure.</p>
<p>Within the test folder, create 3 files named `chmod-XXX.sh`. Each script has file 
permissions set corresponding with their file names (`chmod-777.sh` = `chmod 777`). Below each 
file and permissions can be seen.</p>
<p>```console
$ ls -lart test 
total 24
-rwxrwxrwx   1 user  group   11 May 19 13:15 chmod-777.sh
-rw-rw-rw-   1 user  group   11 May 19 13:16 chmod-666.sh
drwxr-xr-x   5 user  group  160 May 19 13:19 .
-rw-rw-r--   1 user  group   11 May 19 13:19 chmod-664.sh
drwxr-xr-x  10 user  group  320 May 19 13:29 ..
```</p>
<p>Below is the snippet nfpm configuration file of the contents of the package. The test folder 
and files has no extra config for enforcing permissions.</p>
<p>```yaml
contents:
- src: foo-binary
  dst: /usr/bin/bar
- src: bar-config.conf
  dst: /etc/foo-binary/bar-config.conf
  type: config
- src: test
  dst: /etc/test/scripts
```</p>
<p>The next step is to create a deb package.</p>
<p>```console
$ nfpm package -p deb # Create dep package
using deb packager...
created package: foo_1.0.0_arm64.deb
```</p>
<p>When on a Ubuntu VM, install the foo pack…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w7jw-q4fg-qc4c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-32698</id>
    <title>gsd-2023-32698</title>
    <updated>2026-10-10T19:55:16.099386+00:00</updated>
    <content>gsd-2023-32698</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-32698"/>
  </entry>
</feed>
