CVE-2008-3907
Publication date 4 September 2008
Last updated 24 July 2024
Ubuntu priority
Description
The open-in-browser command in newsbeuter before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a feed URL.
Notes
jdstrand
per Debian: versions < 1.0-1 didn't include a patch to wrap long article URLs so the crafted part of the URL can be hidden. This of course only affects people not reading articles in the built-in reader.