|
|
| |
|
| |
changetrack: shell command execution
| Package(s): | changetrack |
CVE #(s): | CVE-2009-3233
|
| Created: | September 22, 2009 |
Updated: | September 23, 2009 |
| Description: |
From the Debian advisory:
Marek Grzybowski discovered that changetrack, a program to monitor
changes to (configuration) files, is prone to shell command injection
via metacharacters in filenames. The behaviour of the program has been
adjusted to reject all filenames with metacharacters.
|
| Alerts: |
|
( Log in to post comments)
|
|
|