<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 20:54:02 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-210120</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-210120</link>
      <description>EUVD-2026-210120</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-210120</guid>
    </item>
    <item>
      <title>fkie_cve-2023-32698</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-32698</link>
      <description>&lt;p&gt;nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packaged 
the files (without extra config for enforcing it’s own permissions) files could go out with bad permissions (chmod 666 or 777). Anyone using nfpm for creating packages without checking/setting file permissions before packaging could result in bad permissions for files/folders.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packaged 
the files (without extra config for enforcing it’s own permissions) files could go out with bad permissions (chmod 666 or 777). Anyone using nfpm for creating packages without checking/setting file permissions before packaging could result in bad permissions for files/folders.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-32698</guid>
    </item>
    <item>
      <title>GHSA-w7jw-q4fg-qc4c — nfpm has incorrect default permissions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w7jw-q4fg-qc4c</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/goreleaser/nfpm/v2, Go: github.com/goreleaser/nfpm&lt;/p&gt;
&lt;p&gt;### Summary
When building packages directly from source control, file permissions on the checked-in files are not maintained.&lt;/p&gt;
&lt;p&gt;### Details
When building packages directly from source control, file permissions on the checked-in files are not maintained. When nfpm packaged the files (without extra config for enforcing its own permissions) files could go out with bad permissions (chmod 666 or 777).&lt;/p&gt;
&lt;p&gt;### PoC
Create a default nfpm structure.&lt;/p&gt;
&lt;p&gt;Within the test folder, create 3 files named `chmod-XXX.sh`. Each script has file 
permissions set corresponding with their file names (`chmod-777.sh` = `chmod 777`). Below each 
file and permissions can be seen.&lt;/p&gt;
&lt;p&gt;```console
$ ls -lart test 
total 24
-rwxrwxrwx   1 user  group   11 May 19 13:15 chmod-777.sh
-rw-rw-rw-   1 user  group   11 May 19 13:16 chmod-666.sh
drwxr-xr-x   5 user  group  160 May 19 13:19 .
-rw-rw-r--   1 user  group   11 May 19 13:19 chmod-664.sh
drwxr-xr-x  10 user  group  320 May 19 13:29 ..
```&lt;/p&gt;
&lt;p&gt;Below is the snippet nfpm configuration file of the contents of the package. The test folder 
and files has no extra config for enforcing permissions.&lt;/p&gt;
&lt;p&gt;```yaml
contents:
- src: foo-binary
  dst: /usr/bin/bar
- src: bar-config.conf
  dst: /etc/foo-binary/bar-config.conf
  type: config
- src: test
  dst: /etc/test/scripts
```&lt;/p&gt;
&lt;p&gt;The next step is to create a deb package.&lt;/p&gt;
&lt;p&gt;```console
$ nfpm package -p deb # Create dep package
using deb packager...
created package: foo_1.0.0_arm64.deb
```&lt;/p&gt;
&lt;p&gt;When on a Ubuntu VM, install the foo pack…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/goreleaser/nfpm/v2, Go: github.com/goreleaser/nfpm&lt;/p&gt;
&lt;p&gt;### Summary
When building packages directly from source control, file permissions on the checked-in files are not maintained.&lt;/p&gt;
&lt;p&gt;### Details
When building packages directly from source control, file permissions on the checked-in files are not maintained. When nfpm packaged the files (without extra config for enforcing its own permissions) files could go out with bad permissions (chmod 666 or 777).&lt;/p&gt;
&lt;p&gt;### PoC
Create a default nfpm structure.&lt;/p&gt;
&lt;p&gt;Within the test folder, create 3 files named `chmod-XXX.sh`. Each script has file 
permissions set corresponding with their file names (`chmod-777.sh` = `chmod 777`). Below each 
file and permissions can be seen.&lt;/p&gt;
&lt;p&gt;```console
$ ls -lart test 
total 24
-rwxrwxrwx   1 user  group   11 May 19 13:15 chmod-777.sh
-rw-rw-rw-   1 user  group   11 May 19 13:16 chmod-666.sh
drwxr-xr-x   5 user  group  160 May 19 13:19 .
-rw-rw-r--   1 user  group   11 May 19 13:19 chmod-664.sh
drwxr-xr-x  10 user  group  320 May 19 13:29 ..
```&lt;/p&gt;
&lt;p&gt;Below is the snippet nfpm configuration file of the contents of the package. The test folder 
and files has no extra config for enforcing permissions.&lt;/p&gt;
&lt;p&gt;```yaml
contents:
- src: foo-binary
  dst: /usr/bin/bar
- src: bar-config.conf
  dst: /etc/foo-binary/bar-config.conf
  type: config
- src: test
  dst: /etc/test/scripts
```&lt;/p&gt;
&lt;p&gt;The next step is to create a deb package.&lt;/p&gt;
&lt;p&gt;```console
$ nfpm package -p deb # Create dep package
using deb packager...
created package: foo_1.0.0_arm64.deb
```&lt;/p&gt;
&lt;p&gt;When on a Ubuntu VM, install the foo pack…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w7jw-q4fg-qc4c</guid>
    </item>
    <item>
      <title>gsd-2023-32698</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-32698</link>
      <description>gsd-2023-32698</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-32698</guid>
    </item>
  </channel>
</rss>
