CVE-2008-3907
Publication date 4 September 2008
Last updated 24 July 2024
Ubuntu priority
The open-in-browser command in newsbeuter before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a feed URL.
Status
Package | Ubuntu Release | Status |
---|---|---|
newsbeuter | 8.10 intrepid |
Fixed 0.9.1-1+lenny3
|
8.04 LTS hardy |
Fixed 0.7-1ubuntu0.1
|
|
7.10 gutsy | Ignored end of life, was needed | |
7.04 feisty | Not in release | |
6.06 LTS dapper | Not in release |
Notes
jdstrand
per Debian: versions < 1.0-1 didn’t include a patch to wrap long article URLs so the crafted part of the URL can be hidden. This of course only affects people not reading articles in the built-in reader.