USN-4585-1: Newsbeuter vulnerabilities
Publication date
15 October 2020
Overview
Newsbeuter could be made to crash or run programs as your login if it opened a malicious file.
Releases
Packages
- newsbeuter - open-source RSS/Atom feed reader for text terminals
Details
It was discovered that Newsbeuter didn’t handle the command line input
properly. An remote attacker could use it to ran remote code by crafting
a special input file. (CVE-2017-12904)
It was discovered that Newsbeuter didn’t handle metacharacters in its
filename properly. An remote attacker could use it to ran remote code by
crafting a special filename. (CVE-2017-14500)
It was discovered that Newsbeuter didn’t handle the command line input
properly. An remote attacker could use it to ran remote code by crafting
a special input file. (CVE-2017-12904)
It was discovered that Newsbeuter didn’t handle metacharacters in its
filename properly. An remote attacker could use it to ran remote code by
crafting a special filename. (CVE-2017-14500)
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
16.04 xenial | newsbeuter – 2.9-3ubuntu0.1 |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.