6.8
CVSSv2

CVE-2014-0479

Published: 06/08/2014 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

reportbug prior to 6.4.4+deb7u1 and 6.5.x prior to 6.5.0+nmu1 allows remote malicious users to execute arbitrary commands via vectors related to compare_versions and reportbug/checkversions.py.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian reportbug

canonical reportbug

Vendor Advisories

Jakub Wilk discovered a remote command execution flaw in reportbug, a tool to report bugs in the Debian distribution A man-in-the-middle attacker could put shell metacharacters in the version number allowing arbitrary code execution with the privileges of the user running reportbug For the stable distribution (wheezy), this problem has been fixed ...