SB2018031111 - Gentoo update for Newsbeuter



SB2018031111 - Gentoo update for Newsbeuter

Published: March 11, 2018 Updated: March 11, 2018

Security Bulletin ID SB2018031111
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) OS Command Injection (CVE-ID: CVE-2017-14500)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Improper Neutralization of Special Elements used in an OS Command in the podcast playback function of Podbeuter in Newsbeuter 0.3 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item with a media enclosure (i.e., a podcast file) that includes shell metacharacters in its filename, related to pb_controller.cpp and queueloader.cpp, a different vulnerability than CVE-2017-12904.


Remediation

Install update from vendor's website.