File _patchinfo of Package patchinfo.17607

<patchinfo incident="17607">
  <issue tracker="bnc" id="1199280">VUL-0: CVE-2022-21950: canna: unsafe handling of /tmp/.iroha_unix</issue>
  <issue tracker="cve" id="2022-21950">VUL-0: CVE-2022-21950: canna: unsafe handling of /tmp/.iroha_unix</issue>
  <packager>qzhao</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for canna</summary>
  <description>This update for canna fixes the following issues:

- CVE-2022-21950: move UNIX socket dir from /tmp to /run to avoid
  local attackers being able to place bogus directories in its stead. Use
  systemd-tmpfiles for cleaning old sockets (boo#1199280).
</description>
</patchinfo>
openSUSE Build Service is sponsored by