On 08/07/2014 07:00 PM, Holger Levsen wrote:
Package : reportbug
Version : 4.12.6+deb6u1
CVE ID : CVE-2014-0479
Fix CVE-2014-0479: Arbitrary code execution in compare_versions.
A man-in-the-middle attacker could put shell metacharacters in the
version number, causing execution of code of their choice.
Not used
--
Frank Baalbergen - System / Network Engineer
T +31 (0)10 2760434 | frank.baalber...@mendix.com | www.mendix.com
--
To UNSUBSCRIBE, email to debian-lts-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: https://lists.debian.org/53e4b0f6.1040...@mendix.com