USN-8858-1: Authen::SASL vulnerability
USN-8858-1
It was discovered that Kdenlive allowed dangerous proxy parameters when processing attacker-controlled project files. An attacker could use this to execute arbitrary commands via the MLT framework's ante/post consumer properties.
The collected bulletin did not provide a separate affected-products list. Check the original bulletin before making an exposure decision.
The publication date reported by the vendor.
We collected the advisory from the official source.