Vulnerability Bulletins |
DSA-3977 newsbeuter - security update |
|
| Affected software | Debian |
|
It was discovered that podbeuter, the podcast fetcher in newsbeuter, atext-mode RSS feed reader, did not properly escape the name of the mediaenclosure (the podcast file), allowing a remote attacker to run anarbitrary shell command on the client machine. This is only exploitableif the file is also played in podbeuter. More info: https://www.debian.org/security/2017/dsa-3977 |
|






