File _patchinfo of Package patchinfo.17607
<patchinfo incident="17607"> <issue tracker="bnc" id="1199280">VUL-0: CVE-2022-21950: canna: unsafe handling of /tmp/.iroha_unix</issue> <issue tracker="cve" id="2022-21950">VUL-0: CVE-2022-21950: canna: unsafe handling of /tmp/.iroha_unix</issue> <packager>qzhao</packager> <rating>important</rating> <category>security</category> <summary>Security update for canna</summary> <description>This update for canna fixes the following issues: - CVE-2022-21950: move UNIX socket dir from /tmp to /run to avoid local attackers being able to place bogus directories in its stead. Use systemd-tmpfiles for cleaning old sockets (boo#1199280). </description> </patchinfo>