CVE-2007-5837: Code injection through badly formatted URL
Bug #162351 reported by
William Grant
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
yarssr (Debian) |
Fix Released
|
Unknown
|
|||
yarssr (Ubuntu) |
Fix Released
|
High
|
Unassigned | ||
Dapper |
Fix Released
|
High
|
William Grant | ||
Edgy |
Fix Released
|
High
|
William Grant | ||
Feisty |
Fix Released
|
High
|
William Grant | ||
Gutsy |
Fix Released
|
High
|
William Grant | ||
Hardy |
Fix Released
|
High
|
Unassigned |
Bug Description
Binary package hint: yarssr
GUI.pm in yarssr 0.2.2, when Gnome default URL handling is disabled, allows remote attackers to execute arbitrary commands via shell metacharacters in a link element in a feed.
This affects all supported Ubuntu releases.
Changed in yarssr: | |
assignee: | nobody → fujitsu |
status: | Confirmed → In Progress |
assignee: | nobody → fujitsu |
status: | Confirmed → In Progress |
assignee: | nobody → fujitsu |
status: | Confirmed → In Progress |
assignee: | nobody → fujitsu |
status: | Confirmed → In Progress |
Changed in yarssr: | |
status: | Unknown → Fix Released |
Changed in yarssr: | |
status: | In Progress → Fix Committed |
status: | In Progress → Fix Committed |
status: | In Progress → Fix Committed |
status: | In Progress → Fix Committed |
Changed in yarssr: | |
status: | Fix Committed → Fix Released |
status: | Fix Committed → Fix Released |
To post a comment you must log in.
Fixed in Debian in 0.2.2-3, which we have in Hardy.