MGASA-2018-0059
Dashboard / Vulnerabilities / MGASA-2018-0059
Summary: Updated backintime packages fix security vulnerability
Details: backintime (aka Back in Time) before 1.1.24 did improper escaping/quoting of file paths used as arguments to the 'notify-send' command, leading to some parts of file paths being executed as shell commands within an os.system call in qt4/plugins/notifyplugin.py. This could allow an attacker to craft an unreadable file with a specific name to run arbitrary shell commands (CVE-2017-16667).
References: https://advisories.mageia.org/MGASA-2018-0059.html, https://bugs.mageia.org/show_bug.cgi?id=22000, https://lists.fedoraproject.org/archives/list/[email protected]/thread/4QNBPN76RX2RKR2K7NEMJMOD576ASBHA/
Affected packages
Package
Name: backintime
Purl: pkg:rpm/mageia/backintime?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
