Candidate: CVE-2017-9736 PublicDate: 2017-06-17 16:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9736 https://contrib.spip.net/CRITICAL-security-update-SPIP-3-1-6-and-SPIP-3-2-Beta https://core.spip.net/projects/spip/repository/revisions/23593 https://core.spip.net/projects/spip/repository/revisions/23594 Description: SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to cause remote code execution. Ubuntu-Description: Notes: seth-arnold> The patches look like this is a simple black-list functionality but doesn't black-list $() or `` or <() or any other number of shell metacharacters. I expect this is still broken and should use a whitelist of a-z0-9_-. msalvatore> "SPIP 3.0.x and earlier versions are not affected by this issue." Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864921 Priority: high Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_spip: upstream: https://core.spip.net/projects/spip/repository/revisions/23593 upstream: https://core.spip.net/projects/spip/repository/revisions/23594 upstream_spip: released (3.1.4-3) precise/esm_spip: DNE trusty_spip: ignored (reached end-of-life) trusty/esm_spip: DNE (trusty was not-affected [code not present]) vivid/ubuntu-core_spip: DNE xenial_spip: not-affected (code not present) yakkety_spip: ignored (reached end-of-life) zesty_spip: ignored (reached end-of-life) artful_spip: not-affected (3.1.4-3) bionic_spip: not-affected (3.1.4-3) cosmic_spip: not-affected (3.1.4-3) disco_spip: not-affected (3.1.4-3) eoan_spip: not-affected (3.1.4-3) devel_spip: not-affected (3.1.4-3)