changetrack: shell command execution
| Package(s): | changetrack | CVE #(s): | CVE-2009-3233 | ||||
| Created: | September 22, 2009 | Updated: | September 23, 2009 | ||||
| Description: | From the Debian advisory: Marek Grzybowski discovered that changetrack, a program to monitor changes to (configuration) files, is prone to shell command injection via metacharacters in filenames. The behaviour of the program has been adjusted to reject all filenames with metacharacters. | ||||||
| Alerts: |
| ||||||
