USN-4585-1: Newsbeuter vulnerabilities
15 October 2020
Newsbeuter could be made to crash or run programs as your login if it opened a malicious file.
Releases
Packages
- newsbeuter - open-source RSS/Atom feed reader for text terminals
Details
It was discovered that Newsbeuter didn't handle the command line input
properly. An remote attacker could use it to ran remote code by crafting
a special input file. (CVE-2017-12904)
It was discovered that Newsbeuter didn't handle metacharacters in its
filename properly. An remote attacker could use it to ran remote code by
crafting a special filename. (CVE-2017-14500)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
In general, a standard system update will make all the necessary changes.