PT-2017-13491 · Newsbeuter+3 · Newsbeuter+3

Noctux

·

Publicado

2017-09-17

·

Atualizado

2020-10-21

·

CVE-2017-14500

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Newsbeuter versions 0.3 through 2.9
Description The issue is related to improper neutralization of special elements used in an OS command in the podcast playback function of Podbeuter. This allows remote attackers to perform user-assisted code execution by crafting an RSS item with a media enclosure that includes shell metacharacters in its filename. The issue is related to the files pb controller.cpp and queueloader.cpp.
Recommendations For Newsbeuter versions 0.3 through 2.9, consider disabling the podcast playback function until a patch is available to prevent user-assisted code execution. Restrict access to the podcast feature to minimize the risk of exploitation. Avoid using the podcast playback function with RSS items that include media enclosures with potentially malicious filenames. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2368
CVE-2017-14500
DLA-1104-1
DSA-3977-1
OPENSUSE-SU-2018_0229-1
USN-4585-1

Produtos afetados

Alt Linux
Newsbeuter
Suse
Ubuntu