Vulnerability Bulletins

DSA-3977 newsbeuter - security update

   
Affected software Debian
 
It was discovered that podbeuter, the podcast fetcher in newsbeuter, atext-mode RSS feed reader, did not properly escape the name of the mediaenclosure (the podcast file), allowing a remote attacker to run anarbitrary shell command on the client machine. This is only exploitableif the file is also played in podbeuter.

More info:

https://www.debian.org/security/2017/dsa-3977