GLSA-201801-18 : Newsbeuter: User-assisted execution of arbitrary code
Medium Nessus Plugin ID 106117
SynopsisThe remote Gentoo host is missing one or more security-related patches.
DescriptionThe remote host is affected by the vulnerability described in GLSA-201801-18 (Newsbeuter: User-assisted execution of arbitrary code)
Newsbeuter does not properly escape shell meta-characters in the title and description of RSS feeds when bookmarking.
A remote attacker, by enticing a user to open a feed with specially crafted URLs, could possibly execute arbitrary shell commands with the privileges of the user running the application.
There is no known workaround at this time.
SolutionAll Newsbeuter users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=net-news/newsbeuter-2.9-r3'