Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item that includes shell code in its title and/or URL.
{ "vanir_signatures": [ { "target": { "file": "src/controller.cpp", "function": "controller::bookmark" }, "id": "CVE-2017-12904-80defa35", "source": "https://github.com/akrennmair/newsbeuter/commit/96e9506ae9e252c548665152d1b8968297128307", "digest": { "length": 1137.0, "function_hash": "156371956141367904438567274571704191043" }, "signature_version": "v1", "signature_type": "Function", "deprecated": false }, { "target": { "file": "src/controller.cpp" }, "id": "CVE-2017-12904-a213a0e6", "source": "https://github.com/akrennmair/newsbeuter/commit/96e9506ae9e252c548665152d1b8968297128307", "digest": { "line_hashes": [ "311467814947250909956345134156606465782", "120649832345985744059501555645473888522", "291634685458980627202111577571935776043", "69626142850719159396634039256131327469", "108602646767993423147163902786916057536", "98085112480429494262981916468034871801", "92970788905403075723020112092901087587", "252124518186464253228361430297539845061", "254514588870447734634416090126986229927" ], "threshold": 0.9 }, "signature_version": "v1", "signature_type": "Line", "deprecated": false } ] }