/usr/bin/shutter in Shutter up to and including 0.93.1 allows user-assisted remote malicious users to execute arbitrary commands via a crafted image name that is mishandled during a "Run a plugin" action.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
shutter-project shutter |