Candidate: CVE-2017-12904 PublicDate: 2017-08-23 14:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12904 https://github.com/akrennmair/newsbeuter/issues/591 https://github.com/akrennmair/newsbeuter/commit/96e9506ae9e252c548665152d1b8968297128307 Description: Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item that includes shell code in its title and/or URL. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_newsbeuter: upstream_newsbeuter: released (2.9-6) precise/esm_newsbeuter: DNE trusty_newsbeuter: ignored (reached end-of-life) trusty/esm_newsbeuter: DNE (trusty was needed) vivid/ubuntu-core_newsbeuter: DNE xenial_newsbeuter: released (2.9-3ubuntu0.1) zesty_newsbeuter: released (2.9-5+deb9u1build0.17.04.1) artful_newsbeuter: not-affected (2.9-6) bionic_newsbeuter: not-affected (2.9-6) cosmic_newsbeuter: not-affected (2.9-6) disco_newsbeuter: not-affected (2.9-6) eoan_newsbeuter: DNE focal_newsbeuter: DNE devel_newsbeuter: DNE