7.8
CVSSv3

CVE-2016-10081

Published: 29/12/2016 Updated: 07/11/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

/usr/bin/shutter in Shutter up to and including 0.93.1 allows user-assisted remote malicious users to execute arbitrary commands via a crafted image name that is mishandled during a "Run a plugin" action.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

shutter-project shutter

Vendor Advisories

Debian Bug report logs - #849777 shutter: CVE-2016-10081: Insecure use of perl exec() Package: src:shutter; Maintainer for src:shutter is Ryan Niebur <ryan@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 30 Dec 2016 21:39:05 UTC Severity: grave Tags: pending, security, upstream Found in ...

Exploits

# Exploit Title: Shutter user-assisted remote code execution # Date: 2016-12-26 # Software Link: shutter-projectorg/ # Version: 0931 # Tested on: Ubuntu, Debian # Exploit Author: Prajith P # Website: prajithin/ # Author Mail: me@prajithin # CVE: CVE-2016-10081 1 Description /usr/bin/shutter in Shutter through 0931 allows ...
Shutter version 0931 suffers from a code execution vulnerability ...