Vulnerability Bulletins

DSA-3949 augeas - security update

   
Affected software Debian
 
Han Han of Red Hat discovered that augeas, a configuration editingtool, improperly handled some escaped strings. A remote attacker couldleverage this flaw by sending maliciously crafted strings, thuscausing an augeas-enabled application to crash or potentially executearbitrary code.

More info:

https://www.debian.org/security/2017/dsa-3949