Bug#587205: feh: Arbitrary code execution with --wget-timestamp and URLs

2010-06-27 Thread Thijs Kinkhorst
Hi Daniel, On sneon 26 Juny 2010, Daniel Friesel wrote: there exists an (IMHO rather unlikely, but still possible) arbitrary code execution hole in feh. All versions = 1.7 down to at least the 1.3.4 in stable (I didn't check earlier ones) are affected. See

Bug#587205: feh: Arbitrary code execution with --wget-timestamp and URLs

2010-06-26 Thread Daniel Friesel
Package: feh Version: 1.3.4.dfsg.1-1 Severity: grave Tags: security Justification: user security hole Hello, there exists an (IMHO rather unlikely, but still possible) arbitrary code execution hole in feh. All versions = 1.7 down to at least the 1.3.4 in stable (I didn't check earlier ones) are