Package: newsbeuter / 2.8-2+deb8u2
Metadata
Package | Version | Patches format |
---|---|---|
newsbeuter | 2.8-2+deb8u2 | 3.0 (quilt) |
Patch series
view the series filePatch | File delta | Description |
---|---|---|
1 fix RCE on bookmark.patch | (download) |
src/controller.cpp |
7 4 + 3 - 0 ! |
fix a rce vulnerability on the bookmark command Newsbeuter didn't properly escape the title and description fields before passing them to the bookmarking program which could lead to remote code execution using the shells command substitution functionality (e.g. "$()", ``, etc) |
2 Work around shell code in podcast names 598.patch | (download) |
src/pb_controller.cpp |
6 3 + 3 - 0 ! |
work around shell code in podcast names (#598) |
1