Debian · Reportbug · CVE-2008-2230
Name of the Vulnerable Software and Affected Versions:
reportbug versions 3.8 through 3.31
reportbug-ng versions prior to 0.2008.06.04
Description:
The issue allows local users to execute arbitrary code via a malicious module file in the current working directory. This is due to an untrusted search path vulnerability.
Recommendations:
For reportbug versions 3.8 through 3.31, update to a version later than 3.31 to resolve the issue.
For reportbug-ng versions prior to 0.2008.06.04, update to version 0.2008.06.04 or later to resolve the issue.