UBUNTU-CVE-2017-14500
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-14500
UBUNTU-CVE-2017-14500
Summary:
Details: Improper Neutralization of Special Elements used in an OS Command in the podcast playback function of Podbeuter in Newsbeuter 0.3 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item with a media enclosure (i.e., a podcast file) that includes shell metacharacters in its filename, related to pb_controller.cpp and queueloader.cpp, a different vulnerability than CVE-2017-12904.
References: https://ubuntu.com/security/CVE-2017-14500, http://openwall.com/lists/oss-security/2017/09/16/1, https://www.cve.org/CVERecord?id=CVE-2017-14500, https://ubuntu.com/security/notices/USN-4585-1
Affected packages
Package
Name: newsbeuter
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
