Debian Package Tracker
Register | Log in
Subscribe

flameshot

Powerful yet simple-to-use screenshot software

Choose email to subscribe with

general
  • source: flameshot (main)
  • version: 14.0.0-3
  • maintainer: Chow Loong Jin (DMD)
  • arch: any
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 0.9.0+ds1-2+deb11u2
  • oldstable: 12.1.0-2
  • stable: 12.1.0+ds-2
  • stable-bpo: 13.3.0+git20251204-1~bpo13+1
  • testing: 14.0.0-3
  • unstable: 14.0.0-3
versioned links
  • 0.9.0+ds1-2+deb11u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 12.1.0-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 12.1.0+ds-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 13.3.0+git20251204-1~bpo13+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 14.0.0-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • flameshot (9 bugs: 1, 7, 1, 0)
action needed
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-62294: Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same machine to pre-plant a symlink and cause Flameshot to write PNG data through it, overwriting any file the victim user could write. This issue is fixed in version 14.0.0.
Created: 2026-07-16 Last update: 2026-07-18 07:31
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2026-62294: Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same machine to pre-plant a symlink and cause Flameshot to write PNG data through it, overwriting any file the victim user could write. This issue is fixed in version 14.0.0.
Created: 2026-07-16 Last update: 2026-07-18 07:31
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-62294: Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same machine to pre-plant a symlink and cause Flameshot to write PNG data through it, overwriting any file the victim user could write. This issue is fixed in version 14.0.0.
Created: 2026-07-16 Last update: 2026-07-18 07:31
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.2).
Created: 2025-12-23 Last update: 2026-07-13 12:19
news
[rss feed]
  • [2026-07-18] flameshot 14.0.0-3 MIGRATED to testing (Debian testing watch)
  • [2026-07-13] Accepted flameshot 14.0.0-3 (source) into unstable (Chow Loong Jin)
  • [2026-07-11] Accepted flameshot 14.0.0-2 (source) into unstable (Chow Loong Jin)
  • [2026-07-07] Accepted flameshot 14.0.0-1 (source) into unstable (Chow Loong Jin)
  • [2026-05-21] flameshot 13.3.0+git20251204-2 MIGRATED to testing (Debian testing watch)
  • [2026-05-14] Accepted flameshot 13.3.0+git20251204-2 (source) into unstable (Doglas Franco Maurer da Rocha) (signed by: Marcos Talau)
  • [2025-12-12] Accepted flameshot 13.3.0+git20251204-1~bpo13+1 (source) into stable-backports (Boyuan Yang)
  • [2025-12-11] flameshot 13.3.0+git20251204-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-05] Accepted flameshot 13.3.0+git20251204-1 (source) into unstable (Boyuan Yang)
  • [2025-12-05] Accepted flameshot 13.3.0-2 (source) into unstable (Boyuan Yang)
  • [2025-12-05] Accepted flameshot 13.3.0-1~bpo13+1 (source amd64) into stable-backports (Debian FTP Masters) (signed by: Boyuan Yang)
  • [2025-12-02] flameshot 13.3.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-27] Accepted flameshot 13.3.0-1 (source) into unstable (Boyuan Yang)
  • [2025-11-04] flameshot 12.1.0+ds-4 MIGRATED to testing (Debian testing watch)
  • [2025-10-29] Accepted flameshot 12.1.0+ds-4 (source) into unstable (David da Silva Polverari)
  • [2025-10-02] flameshot 12.1.0+ds-3 MIGRATED to testing (Debian testing watch)
  • [2025-09-27] Accepted flameshot 12.1.0+ds-3 (source) into unstable (David da Silva Polverari)
  • [2025-02-23] flameshot 12.1.0+ds-2 MIGRATED to testing (Debian testing watch)
  • [2025-02-18] Accepted flameshot 12.1.0+ds-2 (source) into unstable (David da Silva Polverari)
  • [2024-10-28] flameshot 12.1.0+ds-1 MIGRATED to testing (Debian testing watch)
  • [2024-10-23] Accepted flameshot 12.1.0+ds-1 (source) into unstable (David da Silva Polverari)
  • [2024-05-03] flameshot 12.1.0-3 MIGRATED to testing (Debian testing watch)
  • [2024-03-07] Accepted flameshot 12.1.0-3 (source) into unstable (Boyuan Yang)
  • [2023-09-25] Accepted flameshot 0.9.0+ds1-2+deb11u2 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Boyuan Yang)
  • [2023-09-25] Accepted flameshot 0.9.0+ds1-2+deb11u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Boyuan Yang)
  • [2023-03-06] flameshot 12.1.0-2 MIGRATED to testing (Debian testing watch)
  • [2023-02-24] Accepted flameshot 12.1.0-2~bpo11+1 (source) into bullseye-backports (Boyuan Yang)
  • [2023-02-23] Accepted flameshot 12.1.0-2 (source) into unstable (Boyuan Yang)
  • [2022-07-11] flameshot 12.1.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-06] Accepted flameshot 12.1.0-1~bpo11+1 (source) into bullseye-backports (Boyuan Yang)
  • 1
  • 2
bugs [bug history graph]
  • all: 9
  • RC: 1
  • I&N: 7
  • M&W: 1
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 14.0.0-3

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing