Bug 448285 (CVE-2008-2575)
| Summary: | CVE-2008-2575 cbrpager: Command executions via improper shell escaping | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Tomas Hoger <thoger> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | mtasaka |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2008-06-07 17:32:07 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Tomas Hoger
2008-05-25 13:13:09 UTC
Non-security issue is found on 0.9.17-1.fc{10-7}, so updating
to 0.9.17-2.fc{10-7} and editting updates requests.
cbrpager-0.9.17-2.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report. cbrpager-0.9.17-2.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report. cbrpager-0.9.17-2.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report. Upstream released 0.9.18. With this version the following patch is applied http://cvs.fedoraproject.org/viewcvs/*checkout*/rpms/cbrpager/devel/cbrpager-0.9.17-zip-filen-escape.patch?hideattic=0&rev=1.1 cbrpager-0.9.18-1.fc{9,8,7} are now in request queue to stable on bodhi CVE id CVE-2008-2575 was assigned to this issue: cbrPager before 0.9.17 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a (1) ZIP (aka .cbz) or (2) RAR (aka .cbr) archive filename. Fixed for all current Fedora versions via: https://admin.fedoraproject.org/updates/F7/FEDORA-2008-4440 https://admin.fedoraproject.org/updates/F8/FEDORA-2008-4528 https://admin.fedoraproject.org/updates/F9/FEDORA-2008-4501 |