Vulnerability Bulletins

DSA-4052 bzr - security update

   
Affected software Debian
 
Adam Collard discovered that Bazaar, an easy to use distributed versioncontrol system, did not correctly handle maliciously constructed bzr+sshURLs, allowing a remote attacker to run an arbitrary shell command.

More info:

https://www.debian.org/security/2017/dsa-4052