Alpine: multiple liferea packages: security update to 1.14.0-r0 (deprecated)

critical Tenable Cloud Security Plugin ID 400056

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A vulnerability was found in liferea. It has been rated as critical. Affected by this issue is the
function update_job_run of the file src/update.c of the component Feed Enrichment. The manipulation of the
argument source with the input |date >/tmp/bad-item-link.txt leads to os command injection. The attack
may be launched remotely. The exploit has been disclosed to the public and may be used. The name of the
patch is 8d8b5b963fa64c7a2122d1bbfbb0bed46e813e59. It is recommended to apply a patch to fix this issue.
The identifier of this vulnerability is VDB-222848. (CVE-2023-1350)

See Also

https://git.alpinelinux.org/aports/commit/?id=b3eff06ae3ba264f350bd9f3430dbcd1b42c0be5

https://git.alpinelinux.org/aports/commit/?id=e60067207700079145cca95b05892c0f550460f5

Plugin Details

Severity: Critical

ID: 400056

Version: Revision 1.48

Type: Local

Published: 3/13/2023

Updated: 7/20/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2023-1350

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/13/2023

Vulnerability Publication Date: 3/11/2023

Reference Information

CVE: CVE-2023-1350