VDB
Sign up
LOW

GHSA-fq3w-p4fg-mw73

fixurjavainstall: Previous Fuji versions can accidentally wipe `/usr/share/man/man8`

Details

### Impact Affects: Anyone who generates the UNIX man pages in Fuji <= `0.8.0` build with the `dev` crate feature. Consequences: `/usr/share/man/man8` may be entirely removed & re-created without any of the previous entries.

### Patches At the time of writing, no new version has been released on crates.io, due to an unrelated CI/CD publishing issue. Due to the same unrelated publishing issue, no new GitHub Releases version has been released.

### Workarounds Do not run `fuji manual` on non-`dev` builds for versions <= `0.8.0`.

### Additional Information This bug results from development-only code being accidentally left in for release use. Previous versions of Fuji are still "safe" to use, provided that you do not run `fuji manual`. There is no malicious potential from this, it's just a major annoyance to accidentally remove all your sysadmin man pages.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/fixurjavainstall
Introduced in: 0Fixed in: 0.8.1

Upgrade fixurjavainstall to 0.8.1 or newer (ecosystem crates.io).

References