Debian Security Advisory

DLA-31-1 reportbug -- LTS security update

Date Reported:
07 Aug 2014
Affected Packages:
reportbug
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2014-0479.
More information:

Fix CVE-2014-0479: Arbitrary code execution in compare_versions. A man-in-the-middle attacker could put shell metacharacters in the version number, causing execution of code of their choice.

For Debian 6 Squeeze, these issues have been fixed in reportbug version 4.12.6+deb6u1