Skip to content

Greenshot Arbitrary Code Execution Vulnerability #474

Description

@TESTER-sec

It was reported on the Greenshot JIRA that a special file can be created that can exploit Greenshot.

https://greenshot.atlassian.net/jira/software/c/projects/BUG/issues/BUG-3061?filter=allissues

At this point, the project knows about this vulnerability. So it begs the questions - Then why is Greenshot still available for download?

The download link be taken down until a new version with a security fix is released? Also the project should issue a public advisory. If the reported vulnerability will not be fixed anytime soon, then what is the risk to those who use the latest (2017) version?

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions