Vulnerability Bulletins

DSA-4149 plexus-utils2 - security update

   
Affected software Debian
 
Charles Duffy discovered that the Commandline class in the utilities forthe Plexus framework performs insufficient quoting of double-encodedstrings, which could result in the execution of arbitrary shell commands.

More info:

https://www.debian.org/security/2018/dsa-4149