CVE-2008-3907

Publication date 4 September 2008

Last updated 24 July 2024


Ubuntu priority

The open-in-browser command in newsbeuter before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a feed URL.

Read the notes from the security team

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
newsbeuter 8.10 intrepid
Fixed 0.9.1-1+lenny3
8.04 LTS hardy
Fixed 0.7-1ubuntu0.1
7.10 gutsy Ignored end of life, was needed
7.04 feisty Not in release
6.06 LTS dapper Not in release

Notes


jdstrand

per Debian: versions < 1.0-1 didn’t include a patch to wrap long article URLs so the crafted part of the URL can be hidden. This of course only affects people not reading articles in the built-in reader.