LWN.net Logo

comix: arbitrary code execution

Package(s):comix CVE #(s):CVE-2008-1568
Created:April 9, 2008 Updated:April 28, 2008
Description:

From the NVD entry:

comix 3.6.4 allows attackers to execute arbitrary commands via a filename containing shell metacharacters that are not properly sanitized when executing the rar, unrar, or jpegtran programs

Alerts:
Gentoo 200804-29 2008-04-25
Fedora FEDORA-2008-2981 2008-04-08
Fedora FEDORA-2008-2993 2008-04-08

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds