CVE-2008-3907
Published Sep 4, 2008
Last updated 7 years ago
Overview
- Description
- The open-in-browser command in newsbeuter before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a feed URL.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-20
Evaluator
- Comment
- http://www.openwall.com/lists/oss-security/2008/09/01/4 "The previous version allowed to execute arbitrary code by a crafted feed URL that is passed as a command line parameter if the URL is opened by an external browser."
- Impact
- -
- Solution
- -
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:newsbeuter:newsbeuter:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "276F919F-3181-4ADE-A181-7A8776115338", "versionEndIncluding": "1.0" }, { "criteria": "cpe:2.3:a:newsbeuter:newsbeuter:0.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A1E21217-98D9-4FAD-88D4-652746FB05C1" }, { "criteria": "cpe:2.3:a:newsbeuter:newsbeuter:0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DA51EDB2-94CD-421C-B7D9-5E3FEEAD194E" }, { "criteria": "cpe:2.3:a:newsbeuter:newsbeuter:0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4AF4978C-4EBF-41ED-962F-0890E5BDC071" }, { "criteria": "cpe:2.3:a:newsbeuter:newsbeuter:0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DCDA3939-74B1-4A44-955D-1BA1D2A23C0F" }, { "criteria": "cpe:2.3:a:newsbeuter:newsbeuter:0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B242B9F1-3B5B-41EE-8CFF-BCC3008B785A" }, { "criteria": "cpe:2.3:a:newsbeuter:newsbeuter:0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "733B891C-63E6-45A2-AE6D-32A4C860A07D" }, { "criteria": "cpe:2.3:a:newsbeuter:newsbeuter:0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "684B7199-9344-4DBA-90AD-DEDEC056F213" }, { "criteria": "cpe:2.3:a:newsbeuter:newsbeuter:0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "45CD698E-70A1-43A0-B828-3DBD519DDDF9" }, { "criteria": "cpe:2.3:a:newsbeuter:newsbeuter:0.8.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "379E21B5-D427-45EC-B674-9BCC8A47CA76" }, { "criteria": "cpe:2.3:a:newsbeuter:newsbeuter:0.8.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EB0B1B93-8E8C-4A77-98F8-CE5BFED550DF" }, { "criteria": "cpe:2.3:a:newsbeuter:newsbeuter:0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1C907407-E178-43BF-A433-9BC73EB7FD5F" }, { "criteria": "cpe:2.3:a:newsbeuter:newsbeuter:0.9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DB3A20C1-1FB7-43C8-A78E-FBEBB4E888AF" } ], "operator": "OR" } ] } ]