6.8
CVSSv2

CVE-2017-14500

Published: 17/09/2017 Updated: 21/10/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Improper Neutralization of Special Elements used in an OS Command in the podcast playback function of Podbeuter in Newsbeuter 0.3 up to and including 2.9 allows remote malicious users to perform user-assisted code execution by crafting an RSS item with a media enclosure (i.e., a podcast file) that includes shell metacharacters in its filename, related to pb_controller.cpp and queueloader.cpp, a different vulnerability than CVE-2017-12904.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

newsbeuter newsbeuter 0.8.1

newsbeuter newsbeuter 0.8.2

newsbeuter newsbeuter 2.0

newsbeuter newsbeuter 2.1

newsbeuter newsbeuter 2.8

newsbeuter newsbeuter 2.9

newsbeuter newsbeuter 0.3

newsbeuter newsbeuter 0.4

newsbeuter newsbeuter 0.9

newsbeuter newsbeuter 0.9.1

newsbeuter newsbeuter 2.2

newsbeuter newsbeuter 2.3

newsbeuter newsbeuter 0.7

newsbeuter newsbeuter 0.8

newsbeuter newsbeuter 1.2

newsbeuter newsbeuter 1.3

newsbeuter newsbeuter 2.6

newsbeuter newsbeuter 2.7

newsbeuter newsbeuter 0.5

newsbeuter newsbeuter 0.6

newsbeuter newsbeuter 1.0

newsbeuter newsbeuter 1.1

newsbeuter newsbeuter 2.4

newsbeuter newsbeuter 2.5

Vendor Advisories

Debian Bug report logs - #876004 newsbeuter: CVE-2017-14500: Podbeuter podcast fetcher: remote code execution Package: src:newsbeuter; Maintainer for src:newsbeuter is Nikos Tsipinakis <nikos@tsipinakiscom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 17 Sep 2017 09:27:02 UTC Severity: grave Tag ...
It was discovered that podbeuter, the podcast fetcher in newsbeuter, a text-mode RSS feed reader, did not properly escape the name of the media enclosure (the podcast file), allowing a remote attacker to run an arbitrary shell command on the client machine This is only exploitable if the file is also played in podbeuter For the oldstable distribu ...