Vulnerability Bulletins |
DSA-3949 augeas - security update |
|
| Affected software | Debian |
|
Han Han of Red Hat discovered that augeas, a configuration editingtool, improperly handled some escaped strings. A remote attacker couldleverage this flaw by sending maliciously crafted strings, thuscausing an augeas-enabled application to crash or potentially executearbitrary code. More info: https://www.debian.org/security/2017/dsa-3949 |
|






