CVE-2006-6678

Publication date 21 December 2006

Last updated 24 July 2024


Ubuntu priority

The edit_textarea function in form-file.c in Netrik 1.15.4 and earlier does not properly verify temporary filenames when editing textarea fields, which allows attackers to execute arbitrary commands via shell metacharacters in the filename.

Status

Package Ubuntu Release Status
netrik 9.04 jaunty
Fixed 1.15.3-1.1
8.10 intrepid
Fixed 1.15.3-1.1
8.04 LTS hardy
Fixed 1.15.3-1.1
7.10 gutsy
Fixed 1.15.3-1.1
7.04 feisty
Fixed 1.15.3-1.1
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper
Fixed 1.15.3-1sarge1build0.6.06.1