** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2008-0302

** Summary changed:

- [apt-listchanges] [DSA-1465-2] programming error
+ [apt-listchanges] [CVE-2008-0302] programming error

** Description changed:

  Binary package hint: apt-listchanges
  
  References:
  DSA-1465-2 (http://www.debian.org/security/2008/dsa-1465)
  
  Quoting:
  "Felipe Sateler discovered that apt-listchanges, a package change history
  notification tool, used unsafe paths when importing its python libraries.
  This could allow the execution of arbitary shell commands if the root user
  executed the command in a directory which other local users may write
  to."
- 
- Unfortunately the referenced CVE-2008-0302 from DSA-1465-2 doesn't
- exist, possible typo?

-- 
[apt-listchanges] [CVE-2008-0302] programming error
https://bugs.launchpad.net/bugs/183967
You received this bug notification because you are a member of Ubuntu
Bugs, which is the bug contact for Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to